[Security-team] Fwd: [SA20240] mpg123 "III_i_stereo()" Function Buffer Overflow Vulnerability

Igor Zubkov =?iso-8859-1?q?icesik_=CE=C1_mail=2Eru?=
Чт Май 25 14:47:26 MSD 2006


В debian уже залатали.

----------  Пересланное сообщение  ----------

Subject: [SA20240] mpg123 "III_i_stereo()" Function Buffer Overflow 
Vulnerability
Date: 25 мая 2006 13:18
From: Secunia Security Advisories <sec-adv на secunia.com>
To: icesik на mail.ru

TITLE:
mpg123 "III_i_stereo()" Function Buffer Overflow Vulnerability

SECUNIA ADVISORY ID:
SA20240

VERIFY ADVISORY:
http://secunia.com/advisories/20240/

CRITICAL:
Highly critical

IMPACT:
System access

WHERE:
From remote

SOFTWARE:
mpg123 0.x
http://secunia.com/product/952/

DESCRIPTION:
A. Alejandro Hernández has reported a vulnerability in mpg123, which
potentially can be exploited by malicious people to compromise a
user's system.

The vulnerability is caused due to a boundary error within the
"III_i_stereo()" function in layer3.c when processing MPEG 2.0 layer
3 files. This can be exploited to cause a buffer overflow when a user
opens a specially crafted MPEG 2.0 layer 3 file.

Successful exploitation may allow execution of arbitrary code.

SOLUTION:
Use another product.

PROVIDED AND/OR DISCOVERED BY:
A. Alejandro Hernández

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/


Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=icesik%40mail.ru

----------------------------------------------------------------------

-------------------------------------------------------

-- 
Linkin Park - Breaking The Habit (live)
----------- следующая часть -----------
Было удалено вложение не в текстовом формате...
Имя     : =?iso-8859-1?q?=CF=D4=D3=D5=D4=D3=D4=D7=D5=C5=D4?=
Тип     : application/pgp-signature
Размер  : 191 байтов
Описание: =?iso-8859-1?q?=CF=D4=D3=D5=D4=D3=D4=D7=D5=C5=D4?=
Url     : <http://lists.altlinux.org/pipermail/security-team/attachments/20060525/2bcfe3d9/attachment-0003.bin>


Подробная информация о списке рассылки Security-team