Submitted by KeesCook on Tue, 2007-03-27 23:06.
usn
Referenced CVEs:
CVE-2007-0653, CVE-2007-0654
Description:
===========================================================
Ubuntu Security Notice USN-445-1 March 27, 2007
xmms vulnerabilities
CVE-2007-0653, CVE-2007-0654
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 5.10
Ubuntu 6.06 LTS
Ubuntu 6.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 5.10:
xmms 1.2.10+cvs20050209-2ubuntu2.1
Ubuntu 6.06 LTS:
xmms 1.2.10+cvs20050809-4ubuntu5.1
Ubuntu 6.10:
xmms 1.2.10+cvs20060429-1ubuntu2.1
After a standard system upgrade you need to restart XMMS or reboot your
computer to effect the necessary changes.
Details follow:
Sven Krewitt of Secunia Research discovered that XMMS did not correctly
handle BMP images when loading GUI skins. If a user were tricked into
loading a specially crafted skin, a remote attacker could execute
arbitrary code with user privileges.


