[Security-team] Fwd: [SA20240] mpg123 "III_i_stereo()" Function Buffer Overflow Vulnerability
Igor Zubkov
=?iso-8859-1?q?icesik_=CE=C1_mail=2Eru?=
Чт Май 25 14:47:26 MSD 2006
В debian уже залатали.
---------- Пересланное сообщение ----------
Subject: [SA20240] mpg123 "III_i_stereo()" Function Buffer Overflow
Vulnerability
Date: 25 мая 2006 13:18
From: Secunia Security Advisories <sec-adv на secunia.com>
To: icesik на mail.ru
TITLE:
mpg123 "III_i_stereo()" Function Buffer Overflow Vulnerability
SECUNIA ADVISORY ID:
SA20240
VERIFY ADVISORY:
http://secunia.com/advisories/20240/
CRITICAL:
Highly critical
IMPACT:
System access
WHERE:
From remote
SOFTWARE:
mpg123 0.x
http://secunia.com/product/952/
DESCRIPTION:
A. Alejandro Hernández has reported a vulnerability in mpg123, which
potentially can be exploited by malicious people to compromise a
user's system.
The vulnerability is caused due to a boundary error within the
"III_i_stereo()" function in layer3.c when processing MPEG 2.0 layer
3 files. This can be exploited to cause a buffer overflow when a user
opens a specially crafted MPEG 2.0 layer 3 file.
Successful exploitation may allow execution of arbitrary code.
SOLUTION:
Use another product.
PROVIDED AND/OR DISCOVERED BY:
A. Alejandro Hernández
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=icesik%40mail.ru
----------------------------------------------------------------------
-------------------------------------------------------
--
Linkin Park - Breaking The Habit (live)
----------- следующая часть -----------
Было удалено вложение не в текстовом формате...
Имя : =?iso-8859-1?q?=CF=D4=D3=D5=D4=D3=D4=D7=D5=C5=D4?=
Тип : application/pgp-signature
Размер : 191 байтов
Описание: =?iso-8859-1?q?=CF=D4=D3=D5=D4=D3=D4=D7=D5=C5=D4?=
Url : <http://lists.altlinux.org/pipermail/security-team/attachments/20060525/2bcfe3d9/attachment-0003.bin>
Подробная информация о списке рассылки Security-team