xine-lib security vulnerability
Tim van der Molen <[email protected]> Sun, 16 Oct 2005 16:00:32 +0200
| Newsgroups | gmane.linux.lfs.beyond.devel,gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
"By setting up a malicious CDDB server, an attacker can overwrite arbitrary memory locations with arbitrary data." Among the affected versions are all 1.0 releases up to and including 1.0.2, and 1.1.0. The problem is solved in version 1.0.3a. A patch against CVS is also available. A workaround is to delete the xineplug_inp_cdda.so file. More information: <http://xinehq.de/index.php/security/XSA-2005-1>. Regards, Tim -- http://linuxfromscratch.org/mailman/listinfo/blfs-dev FAQ: http://www.linuxfromscratch.org/blfs/faq.html Unsubscribe: See the above information page