GLSA-200404-20 : Multiple vulnerabilities in xine

medium Nessus Plugin ID 14485

Synopsis

The remote Gentoo host is missing one or more security-related patches.

Description

The remote host is affected by the vulnerability described in GLSA-200404-20 (Multiple vulnerabilities in xine)

Several vulnerabilities were found in xine-ui and xine-lib. By opening a malicious MRL in any xine-lib based media player, an attacker can write arbitrary content to an arbitrary file, only restricted by the permissions of the user running the application. By opening a malicious playlist in the xine-ui media player, an attacker can write arbitrary content to an arbitrary file, only restricted by the permissions of the user running xine-ui. Finally, a temporary file is created in an insecure manner by the xine-check and xine-bugreport scripts, potentially allowing a local attacker to use a symlink attack.
Impact :

These three vulnerabilities may allow an attacker to corrupt system files, thus potentially leading to a Denial of Service. It is also theoretically possible, though very unlikely, to use these vulnerabilities to elevate the privileges of the attacker.
Workaround :

There is no known workaround at this time. All users are advised to upgrade to the latest available versions of xine-ui and xine-lib.

Solution

All users of xine-ui or another xine-based player should upgrade to the latest stable versions:
# emerge sync # emerge -pv '>=media-video/xine-ui-0.9.23-r2' # emerge '>=media-video/xine-ui-0.9.23-r2' # emerge -pv '>=media-libs/xine-lib-1_rc3-r3' # emerge '>=media-libs/xine-lib-1_rc3-r3'

See Also

http://xinehq.de/index.php/security

http://nettwerked.mg2.org/advisories/xinebug

https://security.gentoo.org/glsa/200404-20

Plugin Details

Severity: Medium

ID: 14485

File Name: gentoo_GLSA-200404-20.nasl

Version: 1.17

Type: local

Published: 8/30/2004

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.2

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:gentoo:linux:xine-lib, p-cpe:/a:gentoo:linux:xine-ui, cpe:/o:gentoo:linux

Required KB Items: Host/local_checks_enabled, Host/Gentoo/release, Host/Gentoo/qpkg-list

Patch Publication Date: 4/27/2004

Vulnerability Publication Date: 4/22/2004

Reference Information

CVE: CVE-2004-0372, CVE-2004-1951

GLSA: 200404-20