SUSE update for xine
Secunia Advisory: SA23829
Release Date: 2007-01-23
Popularity: 5,015 views

Critical:
Moderately critical
Impact: DoS
System access
Where: From remote
Solution Status: Vendor Patch

OS:SUSE Linux 10
SUSE Linux 10.1
SUSE Linux 9.3

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2007-0254


Description:
SUSE has issued an update for xine-ui, xine-lib, xine-extra and xine-devel. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.

For more information:
SA23709

Solution:
Apply updated packages.

x86 Platform:

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/xine-devel-1.1.2-40.1.i586.rpm
2cacbb4f4e177362149518481480165a
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/xine-extra-1.1.2-40.1.i586.rpm
73cbdd8d443596547875804bd8e2ca8f
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/xine-lib-1.1.2-40.1.i586.rpm
2114f7c6a4c8351adab588c173419778
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/xine-ui-0.99.4-84.1.i586.rpm
5d4dd945a812ba0b17619c267ec8f2b5

SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/xine-extra-1.1.1-24.17.i586.rpm
3eb1465401e5e1c6f36d8e2d7ca3e114
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/xine-lib-1.1.1-24.17.i586.rpm
e2fbf53b629e835dbc2558e87fabf926
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/xine-ui-0.99.4-32.14.i586.rpm
d710db4b4d20f7ea4485d16845cb4be2

SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/upda...pm/i586/xine-extra-1.1.0-0.1.i586.rpm
06753ebd3608223077c95c01f8bc3122
ftp://ftp.suse.com/pub/suse/i386/upda.../rpm/i586/xine-lib-1.1.0-0.1.i586.rpm
60ab4fd7c193d687d9484e5691aa3f01
ftp://ftp.suse.com/pub/suse/i386/upda...rpm/i586/xine-ui-0.99.4-84.1.i586.rpm
4bc3f28d7e600fbb78c65f6b0dcfc436

SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/xine-lib-1.0-10.14.i586.rpm
c944ed72f913771f0c2300883573e111
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/xine-ui-1.0-10.14.i586.rpm
cee2a8a9669b429dde4e465e83aae70f

Power PC Platform:

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/xine-lib-1.1.2-40.1.ppc.rpm
a1fcfa82deed685446a213439639a579
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/xine-ui-0.99.4-84.1.ppc.rpm
bc2dcf2266dbb56b1a0291209aad2dd7

SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/xine-extra-1.1.1-24.17.ppc.rpm
c337440571123263478dd2a64059a4e8
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/xine-lib-1.1.1-24.17.ppc.rpm
3cf476901522d7b5abd5bf3cb18484a9
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/xine-ui-0.99.4-32.14.ppc.rpm
a9e762bad246963a7564c1f36a5f0392

SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/upda.../rpm/ppc/xine-extra-1.1.0-0.1.ppc.rpm
930dc314de3ab49a8655e6cdb89ff50d
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/xine-lib-1.1.0-0.1.ppc.rpm
ddd255708abfb433a3497d790491be55
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/xine-ui-0.99.4-84.1.ppc.rpm
827125d558472b685f0f1843d0eb3850

x86-64 Platform:

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10...6_64/xine-devel-1.1.2-40.1.x86_64.rpm
1dac6b23d257670ca7182f018c12a69b
ftp://ftp.suse.com/pub/suse/update/10...6_64/xine-extra-1.1.2-40.1.x86_64.rpm
11dae8e2ecb5a78eb6b1cd39713f6322
ftp://ftp.suse.com/pub/suse/update/10...x86_64/xine-lib-1.1.2-40.1.x86_64.rpm
519480f44a28d4e3cab37aceca7e7c13
ftp://ftp.suse.com/pub/suse/update/10.../xine-lib-32bit-1.1.2-40.1.x86_64.rpm
3b5db06dab41a4ff2a53d22b3f6f6238
ftp://ftp.suse.com/pub/suse/update/10...x86_64/xine-ui-0.99.4-84.1.x86_64.rpm
b1a06bf5fd93c905bf5008859c88690d
ftp://ftp.suse.com/pub/suse/update/10.../xine-ui-32bit-0.99.4-84.1.x86_64.rpm
aa85b56d559aca4960693bad80a451bd

SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10..._64/xine-extra-1.1.1-24.17.x86_64.rpm
72f6cfc29f428a5d7dc40fbcb285cfe6
ftp://ftp.suse.com/pub/suse/update/10...86_64/xine-lib-1.1.1-24.17.x86_64.rpm
34382ef5b0ec94524678bdf842a21ecb
ftp://ftp.suse.com/pub/suse/update/10...xine-lib-32bit-1.1.1-24.17.x86_64.rpm
316fd37892ef25073cf9d6ae11fb510b
ftp://ftp.suse.com/pub/suse/update/10...86_64/xine-ui-0.99.4-32.14.x86_64.rpm
ee0a3ce52f3bf431ced82dbd0148890c

SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/upda...86_64/xine-extra-1.1.0-0.1.x86_64.rpm
83094481db18fb55447a19b86db281ff
ftp://ftp.suse.com/pub/suse/i386/upda.../x86_64/xine-lib-1.1.0-0.1.x86_64.rpm
0e1b36454127be6815d1f52325ee1a70
ftp://ftp.suse.com/pub/suse/i386/upda...4/xine-lib-32bit-1.1.0-0.1.x86_64.rpm
45829c44efd83afaefe570d81f8a7568
ftp://ftp.suse.com/pub/suse/i386/upda...x86_64/xine-ui-0.99.4-84.1.x86_64.rpm
bfe5d54a07d28cb9fef528c0257d4db7

SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/upda.../x86_64/xine-lib-1.0-10.14.x86_64.rpm
e829f9cbd5e02a0498f03a2180b57963
ftp://ftp.suse.com/pub/suse/i386/upda..._64/xine-lib-32bit-9.3-0.1.x86_64.rpm
064665c8b3ac38f71634734c101f1602
ftp://ftp.suse.com/pub/suse/i386/upda...m/x86_64/xine-ui-1.0-10.14.x86_64.rpm
8e7011003db37a1799bbd531ae957a28

Sources:

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/src/xine-lib-1.1.2-40.1.src.rpm
f92b96c21a6e45ede2faa81c9efade83
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/src/xine-ui-0.99.4-84.1.src.rpm
ed0382a57f117bcf04236ca660092afe

SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/src/xine-lib-1.1.1-24.17.src.rpm
1d347a598b2e8dfc5eaa4f7b9c951242

SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/upda.../rpm/src/xine-lib-1.1.0-0.1.nosrc.rpm
d1d2036b46056a00b3c5a0cee5371ad8

SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/src/xine-lib-1.0-10.14.nosrc.rpm
02ae3f6c9a88ec0aabcce701bba20542

SLE SDK 10
http://support.novell.com/techcenter/psdb/3850f4cb30959892275d84ebf0b1dfc6.html

SUSE SLED 10
http://support.novell.com/techcenter/psdb/3850f4cb30959892275d84ebf0b1dfc6.html

Original Advisory:
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0014.html

Other References:
SA23709:
http://secunia.com/advisories/23709/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. phpJobScheduler "installed_config_file" File Inclusion Vulnerabilities // 57 views
2. Subdreamer Light Global Variables SQL Injection Vulnerability // 35 views
3. PluggedOut Blog "index.php" SQL Injection Vulnerabilities // 31 views
4. Microsoft Word Malformed Object Pointer Vulnerability // 18 views
5. phpBB Cross Site Scripting and Unspecified Vulnerabilities // 17 views
6. Avaya Message Storage Server Input Validation Vulnerabilities // 14 views
7. Drupal Content Construction Kit Script Insertion Vulnerabilities // 14 views
8. CS-Cart "cs_cookies" SQL Injection Vulnerability // 13 views
9. Recipes Website "recipeid" and "categoryid" SQL Injection // 12 views
10. phpBB BBcode Script Insertion Vulnerability // 12 views