Mandrake Linux Security Advisory : mplayer (MDKSA-2004:026)

critical Nessus Plugin ID 14125

Synopsis

The remote Mandrake Linux host is missing one or more security updates.

Description

A remotely exploitable buffer overflow vulnerability was found in MPlayer. A malicious host can craft a harmful HTTP header ('Location:'), and trick MPlayer into executing arbitrary code upon parsing that header.

The updated packages contain a patch from the MPlayer development team to correct the problem.

Solution

Update the affected packages.

See Also

http://www.mplayerhq.hu/homepage/design6/news.html

Plugin Details

Severity: Critical

ID: 14125

File Name: mandrake_MDKSA-2004-026.nasl

Version: 1.16

Type: local

Published: 7/31/2004

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/o:mandrakesoft:mandrake_linux:10.0, p-cpe:/a:mandriva:linux:lib64postproc0, p-cpe:/a:mandriva:linux:lib64postproc0-devel, cpe:/o:mandrakesoft:mandrake_linux:9.2, p-cpe:/a:mandriva:linux:libdha0.1, p-cpe:/a:mandriva:linux:libpostproc0, p-cpe:/a:mandriva:linux:libpostproc0-devel, p-cpe:/a:mandriva:linux:mencoder, p-cpe:/a:mandriva:linux:mplayer, p-cpe:/a:mandriva:linux:mplayer-gui

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 4/5/2004

Reference Information

CVE: CVE-2004-0386

MDKSA: 2004:026