GLSA-200403-13 : Remote buffer overflow in MPlayer
Critical Nessus Plugin ID 14464
SynopsisThe remote Gentoo host is missing one or more security-related patches.
DescriptionThe remote host is affected by the vulnerability described in GLSA-200403-13 (Remote buffer overflow in MPlayer)
A vulnerability exists in the MPlayer HTTP parser which may allow an attacker to craft a special HTTP header ('Location:') which will trick MPlayer into executing arbitrary code on the user's computer.
An attacker without privileges may exploit this vulnerability remotely, allowing arbitrary code to be executed in order to gain unauthorized access.
A workaround is not currently known for this issue. All users are advised to upgrade to the latest version of the affected package.
SolutionMPlayer may be upgraded as follows:
x86 and SPARC users should:
# emerge sync # emerge -pv '>=media-video/mplayer-0.92-r1' # emerge '>=media-video/mplayer-0.92-r1' AMD64 users should:
# emerge sync # emerge -pv '>=media-video/mplayer-1.0_pre2-r1' # emerge '>=media-video/mplayer-1.0_pre2-r1' PPC users should:
# emerge sync # emerge -pv '>=media-video/mplayer-1.0_pre3-r2' # emerge '>=media-video/mplayer-1.0_pre3-r2'