<glsa id="200607-07">
<title>xine-lib: Buffer overflow</title>
A buffer overflow has been found in the libmms library shipped with
xine-lib, potentially resulting in the execution of arbitrary code.
<product type="ebuild">xine-lib</product>
<announced>July 20, 2006</announced>
<revised>July 20, 2006: 01</revised>
<package name="media-libs/xine-lib" auto="yes" arch="*">
<unaffected range="ge">1.1.2-r2</unaffected>
<vulnerable range="lt">1.1.2-r2</vulnerable>
xine-lib is the core library of xine, a multimedia player.
There is a stack based overflow in the libmms library included with
xine-lib which can be triggered by malicious use of the send_command,
string_utf16, get_data and get_media_packet functions.
<impact type="normal">
A remote attacker could design a malicious media file that would
trigger the overflow, potentially resulting in the execution of
arbitrary code.
There is no known workaround at this time.
All xine-lib users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose &quot;&gt;=media-libs/xine-lib-1.1.2-r2&quot;</code>
<uri link="">CVE-2006-2200</uri>
<metadata tag="requester" timestamp="Wed, 12 Jul 2006 17:17:02 +0000">
<metadata tag="submitter" timestamp="Wed, 12 Jul 2006 20:18:19 +0000">
<metadata tag="bugReady" timestamp="Mon, 17 Jul 2006 16:55:34 +0000">