|
Mandriva- Advisories MDVSA-2008:046-1: Updated xine-lib package fixes arbitrary code execution vulnerability
Advisories MDVSA-2008:046-1: Updated xine-lib package fixes arbitrary code execution vulnerability
An array index vulnerability found in the FLAC audio demuxer might allow remote attackers to execute arbitrary code via a crafted FLAC tag, which triggers a buffer overflow. Although originally an MPlayer issue, it also affects xine-lib due to code similarity. The updated packages have been patched to prevent this issue.
Update:
The previous update used a bad patch which made Amarok interface very unresponsive while playing FLAC files. This new update fixes the security issue with a better patch.
http://mandrivausers.org/index.php?showtopic=50454
http://mandrivausers.org/index.php?showtopic=50454
Thu, 21 Feb 2008 02:52:22 +0000
|