Your message dated Fri, 15 Feb 2008 15:02:05 +0000
with message-id <[EMAIL PROTECTED]>
and subject line Bug#464532: fixed in mplayer 1.0~rc2-7+lenny1
has caused the Debian Bug report #464532,
regarding mplayer: CVE-2008-0630 buffer overflow via crafted url
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [EMAIL PROTECTED]
immediately.)
--
464532: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464532
Debian Bug Tracking System
Contact [EMAIL PROTECTED] with problems
--- Begin Message ---
Source: mplayer
Severity: grave
Tags: security
Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for mplayer.
CVE-2008-0630[0]:
| Buffer overflow in url.c in MPlayer 1.0rc2 and SVN before r25823
| allows remote attackers to execute arbitrary code via a crafted URL
| that prevents the IPv6 parsing code from setting a pointer to NULL,
| which causes the buffer to be reused by the unescape code.
You can find a patch for this on:
http://svn.mplayerhq.hu/mplayer/trunk/stream/stream_cddb.c?r1=25820&r2=25824
If you fix this vulnerability please also include the CVE id
in your changelog entry.
For further information:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0630
Kind regards
Nico
--
Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.
pgprUWaWurG5S.pgp
Description: PGP signature
--- End Message ---
--- Begin Message ---
Source: mplayer
Source-Version: 1.0~rc2-7+lenny1
We believe that the bug you reported is fixed in the latest version of
mplayer, which is due to be installed in the Debian FTP archive:
mplayer-doc_1.0~rc2-7+lenny1_all.deb
to pool/main/m/mplayer/mplayer-doc_1.0~rc2-7+lenny1_all.deb
mplayer_1.0~rc2-7+lenny1.diff.gz
to pool/main/m/mplayer/mplayer_1.0~rc2-7+lenny1.diff.gz
mplayer_1.0~rc2-7+lenny1.dsc
to pool/main/m/mplayer/mplayer_1.0~rc2-7+lenny1.dsc
mplayer_1.0~rc2-7+lenny1_i386.deb
to pool/main/m/mplayer/mplayer_1.0~rc2-7+lenny1_i386.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Nico Golde <[EMAIL PROTECTED]> (supplier of updated mplayer package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Fri, 15 Feb 2008 12:35:24 +0100
Source: mplayer
Binary: mplayer mplayer-doc
Architecture: source all i386
Version: 1.0~rc2-7+lenny1
Distribution: testing-security
Urgency: high
Maintainer: A Mennucc1 <[EMAIL PROTECTED]>
Changed-By: Nico Golde <[EMAIL PROTECTED]>
Description:
mplayer - movie player for Unix-like systems
mplayer-doc - documentation for MPlayer
Closes: 464060 464532 464533
Changes:
mplayer (1.0~rc2-7+lenny1) testing-security; urgency=high
.
* Non-maintainer upload by security team.
* This update addresses the following security issues:
- CVE-2008-0630: remote buffer overflow via crafted URL
(Closes: #464532).
- CVE-2008-0629: remote buffer overflow leading to arbitrary
code execution via a crafted CDDB entry (Closes: #464533).
- CVE-2008-0485: array index error in libmpdemux/demux_mov.c
leading to code execution via crafted MOV file (Closes: #464060).
- CVE-2008-0486: array index vulnerability in libmpdemux/demux_audio.c
possibly leading to code execution via crafted FLAC tag.
Files:
e7b91dd0d640af735852b0112d69f612 1435 graphics optional
mplayer_1.0~rc2-7+lenny1.dsc
f1da15bc4accee0a5551928e31d7b779 11727998 graphics optional
mplayer_1.0~rc2.orig.tar.gz
12bee461cc224473a4d52483058ac3bb 71387 graphics optional
mplayer_1.0~rc2-7+lenny1.diff.gz
583ecd8e0d27cd9e91f8e355c643ecb4 2466212 graphics optional
mplayer-doc_1.0~rc2-7+lenny1_all.deb
323b899ca4ac3e199c00f9589129939d 5057120 graphics optional
mplayer_1.0~rc2-7+lenny1_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFHtYGtHYflSXNkfP8RAhpnAJ4hRXN3/psRsQSSAf1dSAOD6WmF5gCeJB9m
LtAMgUpDqS6j6hJF974VHZI=
=0ixp
-----END PGP SIGNATURE-----
--- End Message ---