aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorjosef <josef@FreeBSD.org>2004-12-30 01:34:50 +0800
committerjosef <josef@FreeBSD.org>2004-12-30 01:34:50 +0800
commitb4564de947c0a33b1f589341973c892b6542003f (patch)
treeab36e58337a3196c7308c721d3c399dcbe17aa58
parentfe1da90690c12ce1b241c8b484e531e4fbf5be85 (diff)
downloadfreebsd-ports-gnome-b4564de947c0a33b1f589341973c892b6542003f.tar.gz
freebsd-ports-gnome-b4564de947c0a33b1f589341973c892b6542003f.tar.zst
freebsd-ports-gnome-b4564de947c0a33b1f589341973c892b6542003f.zip
libxine is also affected by the mplayer vulnerabilities.
Add cvenames.
-rw-r--r--security/vuxml/vuln.xml9
1 files changed, 8 insertions, 1 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index f0e4433442de..356664b1e0b4 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -289,6 +289,10 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
<name>mplayer-gtk2-esound</name>
<range><lt>0.99.5_5</lt></range>
</package>
+ <package>
+ <name>libxine</name>
+ <range><le>1.0.r5_3</le></range>
+ </package>
</affects>
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
@@ -302,10 +306,13 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
<li>Potential buffer overflow in mp3lib</li>
</ul>
<p>These vulnerabilities could allow a remote attacker to
- execute arbitrary code as the user running MPlayer.</p>
+ execute arbitrary code as the user running MPlayer. The
+ problem in the pnm streaming code also affects xine.</p>
</body>
</description>
<references>
+ <cvename>CAN-2004-1187</cvename>
+ <cvename>CAN-2004-1188</cvename>
<url>http://mplayerhq.hu/homepage/design7/news.html#mplayer10pre5try2</url>
<mlist msgid="IDSERV04yz5b6KZmcK80000000c@exchange.idefense.com">http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110322526210300</mlist>
<mlist msgid="IDSERV04FVjCRGryWtI0000000f@exchange.idefense.com">http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110322829807443</mlist>