漏洞信息详情
Ffmpeg 图像文件多个缓冲区溢出漏洞
漏洞简介
xine-lib的ffmpeg中存在缓冲区溢出漏洞,依赖于上下文的攻击者可以通过特制的AVI文件和\"错误索引\"执行任意代码。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Ubuntu Ubuntu Linux 6.06 LTS sparc
Ubuntu ffmpeg_0.cvs20050918-5ubuntu1.1_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/f/ffmpeg/ffmpeg_0.cvs2 0050918-5ubuntu1.1_sparc.deb
Ubuntu libavcodec-dev_0.cvs20050918-5ubuntu1.1_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/f/ffmpeg/libavcodec-de v_0.cvs20050918-5ubuntu1.1_sparc.deb
Ubuntu libavformat-dev_0.cvs20050918-5ubuntu1.1_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/f/ffmpeg/libavformat-d ev_0.cvs20050918-5ubuntu1.1_sparc.deb
Ubuntu libpostproc-dev_0.cvs20050918-5ubuntu1.1_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/f/ffmpeg/libpostproc-d ev_0.cvs20050918-5ubuntu1.1_sparc.deb
Ubuntu libxine-dev_1.1.1+ubuntu2-7.3_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/x/xine-lib/libxine-dev_1.1 .1+ubuntu2-7.3_sparc.deb
Ubuntu libxine-main1_1.1.1+ubuntu2-7.3_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/x/xine-lib/libxine-main1_1 .1.1+ubuntu2-7.3_sparc.deb
MPlayer MPlayer 1.0
Mandriva lib64postproc0-1.0-0.pre3.14.8.C30mdk.x86_64.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
Mandriva lib64postproc0-1.0-1.pre7.12.4.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download
Mandriva lib64postproc0-devel-1.0-0.pre3.14.8.C30mdk.x86_64.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
Mandriva lib64postproc0-devel-1.0-1.pre7.12.4.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download
Mandriva libdha0.1-1.0-0.pre3.14.8.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
Mandriva libdha1.0-1.0-1.pre7.12.4.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download
Mandriva libpostproc0-1.0-0.pre3.14.8.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
Mandriva libpostproc0-1.0-1.pre7.12.4.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download
Mandriva libpostproc0-devel-1.0-0.pre3.14.8.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
Mandriva libpostproc0-devel-1.0-1.pre7.12.4.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download
Mandriva mencoder-1.0-0.pre3.14.8.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
Mandriva mencoder-1.0-0.pre3.14.8.C30mdk.x86_64.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
Mandriva mencoder-1.0-1.pre7.12.4.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download
Mandriva mencoder-1.0-1.pre7.12.4.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download
Mandriva mplayer-1.0-0.pre3.14.8.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
Mandriva mplayer-1.0-0.pre3.14.8.C30mdk.x86_64.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
Mandriva mplayer-1.0-1.pre7.12.4.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download
Mandriva mplayer-1.0-1.pre7.12.4.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download
Mandriva mplayer-gui-1.0-0.pre3.14.8.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
Mandriva mplayer-gui-1.0-0.pre3.14.8.C30mdk.x86_64.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
Mandriva mplayer-gui-1.0-1.pre7.12.4.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download
Mandriva mplayer-gui-1.0-1.pre7.12.4.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download
Ubuntu Ubuntu Linux 6.06 LTS powerpc
Ubuntu ffmpeg_0.cvs20050918-5ubuntu1.1_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/f/ffmpeg/ffmpeg_0.cvs2 0050918-5ubuntu1.1_powerpc.deb
Ubuntu libavcodec-dev_0.cvs20050918-5ubuntu1.1_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/f/ffmpeg/libavcodec-de v_0.cvs20050918-5ubuntu1.1_powerpc.de
参考网址
来源: xinehq.de
链接:http://xinehq.de/index.php/news
来源: GENTOO
名称: GLSA-200609-09
链接:http://www.gentoo.org/security/en/glsa/glsa-200609-09.xml
来源: DEBIAN
名称: DSA-1215
链接:http://www.us.debian.org/security/2006/dsa-1215
来源: UBUNTU
名称: USN-358-1
链接:http://www.ubuntu.com/usn/usn-358-1
来源: SUSE
名称: SUSE-SA:2006:073
链接:http://www.novell.com/linux/security/advisories/2006_73_mono.html
来源: SECUNIA
名称: 23213
链接:http://secunia.com/advisories/23213
来源: SECUNIA
名称: 23010
链接:http://secunia.com/advisories/23010
来源: SECUNIA
名称: 22230
链接:http://secunia.com/advisories/22230
受影响实体
- Xine Xine-Lib:1.1.1<!--2000-1-1-->
- Xine Xine-Lib:1.1.0<!--2000-1-1-->
- Xine Xine-Lib:1.0.2<!--2000-1-1-->
- Xine Xine-Lib:1.0.1<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...