Submitted by KeesCook on Mon, 2006-12-04 12:07
Referenced CVEs:
CVE-2006-6172
Description:
===========================================================
Ubuntu Security Notice USN-392-1 December 04, 2006
xine-lib vulnerability
CVE-2006-6172
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 5.10
Ubuntu 6.06 LTS
Ubuntu 6.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 5.10:
libxine1c2 1.0.1-1ubuntu10.7
Ubuntu 6.06 LTS:
libxine-main1 1.1.1+ubuntu2-7.5
Ubuntu 6.10:
libxine1 1.1.2+repacked1-0ubuntu3.2
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
A buffer overflow was discovered in the Real Media input plugin in
xine-lib. If a user were tricked into loading a specially crafted
stream from a malicious server, the attacker could execute arbitrary
code with the user's privileges.


