Xine-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Original]

[xine-devel] Old Security Issue ?


To: Xine DEV ML <xine-devel@xxxxxxxxxxxxxxxxxxxxx>
Subject: [xine-devel] Old Security Issue ?
From: Matthias Hopf <mat@xxxxxxxxx>
Date: Thu, 18 May 2006 18:44:39 +0200
Delivered-to: itdp@localhost
User-agent: Mutt/1.5.9i

Hi all,

we (at SUSE) got this old security issue filed:

http://securitytracker.com/alerts/2006/Apr/1015868.html

I tried to reproduce (an exploit is available, though no explaination),
but the so-called mpeg file that is the 'exploit' is actually an asf
file (call it wmv if you like), and it is appearantly broken, because
xine does not find a demuxer for it. I tried a lot of different
versions, no success.

Has anyone been able to reproduce? How?

Or is this just a hoax?

Matthias

-- 
Matthias Hopf <mhopf@xxxxxxx>       __        __   __
Maxfeldstr. 5 / 90409 Nuernberg    (_   | |  (_   |__         mat@xxxxxxxxx
Phone +49-911-74053-715            __)  |_|  __)  |__  labs   www.mshopf.de


-------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642
_______________________________________________
xine-devel mailing list
xine-devel@xxxxxxxxxxxxxxxxxxxxx
https://lists.sourceforge.net/lists/listinfo/xine-devel


[Prev in Thread] Current Thread [Next in Thread]