|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2004-1309: MPlayer Bitmap Parsing Remote Heap Overflow Vulnerability | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Ludwig Nussel <lnussel> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Major | ||
| Priority: | P3 - Medium | CC: | sbrabec, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | CVE-2004-1309: CVSS v2 Base Score: 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C) | ||
| Found By: | --- | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Bug Depends on: | 64365 | ||
| Bug Blocks: | |||
|
Description
Ludwig Nussel
2004-12-17 19:53:42 UTC
Cummulative patch applied for STABLE and PLUS. For 8.2 and sles9-slec applied only: bmp_fix_20041215_backport.diff, mmst_fix_20041215_backport.diff, mp3_fix_20041215.diff, pnm_fix_20041215.diff. Patch rtsp_fix_20041215.diff not applied, code seems to be completely different. For 8.1 applied only: bmp_fix_20041215_backport.diff, mmst_fix_20041215_backport.diff, mp3_fix_20041215.diff. Patches rtsp_fix_20041215.diff, code seems to be completely different, pnm_fix_20041215.diff, code is probably net yet there. Please verify my backports. For 9.0, 9.1, 9.2 no porting of patch was done! It was never approved for distribution and never tested, or even not compile. Maybe the code should be dropped from there. SM-Tracker-161 I submitted patchinfo-files. Please tell use-dist to build packages. packages approved CVE-2004-1309 CVE-2004-1309: CVSS v2 Base Score: 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C) |