Family: Mandrake Local Security Checks --> Category: infos

MDKSA-2005:228: xine-lib Vulnerability Scan

Vulnerability Scan Summary
Check for the version of the xine-lib package

Detailed Explanation for this Vulnerability Test

The remote host is missing the patch for the advisory MDKSA-2005:228 (xine-lib).

Simon Kilvington discovered a vulnerability in FFmpeg libavcodec, which can be
exploited by malicious people to cause a DoS (Denial of Service) and
potentially to compromise a user's system. The vulnerability is caused due to a
boundary error in the 'avcodec_default_get_buffer()' function of 'utils.c' in
libavcodec. This can be exploited to cause a heap-based buffer overflow when a
specially-crafted 1x1 '.png' file containing a palette is read. Xine-lib is
built with a private copy of ffmpeg containing this same code. (Corporate
Server 2.1 is not vulnerable) The updated packages have been patched to prevent
this problem.

Solution :
Threat Level: High

Threat Level: High


