Pardus: Mplayer Multiple DoS Vulnerabilities


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) Pardus: Mplayer Multiple DoS Vulnerabilities
# 1  
Old 12-18-2008
Pardus: Mplayer Multiple DoS Vulnerabilities

LinuxSecurity.com: Two vulnerabilities have been fixed in ffmpeg which can cause to a DoS (Denial of Service). An endless loop vulnerability when opening corrupt FLV files. A divided by zero vulnerability in sub_packet_size.

More...
Login or Register to Ask a Question

Previous Thread | Next Thread
Login or Register to Ask a Question
MLD(4)							   BSD Kernel Interfaces Manual 						    MLD(4)

NAME
mld -- Multicast Listener Discovery Protocol SYNOPSIS
#include <sys/types.h> #include <sys/socket.h> #include <netinet/in.h> #include <netinet/in_systm.h> #include <netinet/ip6.h> #include <netinet/icmp6.h> #include <netinet6/mld6.h> int socket(AF_INET6, SOCK_RAW, IPPROTO_ICMPV6); DESCRIPTION
MLD is a control plane protocol used by IPv6 hosts and routers to propagate multicast group membership information. Normally this protocol is not used directly, except by the kernel itself, in response to multicast membership requests by user applications. Multicast routing pro- tocol daemons may open a raw socket to directly interact with mld and receive membership reports. As of FreeBSD 8.0, MLD version 2 is implemented. This adds support for Source-Specific Multicast (SSM), whereby applications may communicate to upstream multicast routers that they are only interested in receiving multicast streams from particular sources. The retransmission of state-change reports adds some robustness to the protocol. SYSCTL VARIABLES
net.inet6.mld.stats This opaque read-only variable exposes the stack-wide MLDv2 protocol statistics to netstat(1). net.inet6.mld.ifinfo This opaque read-only variable exposes the per-link MLDv2 status to ifmcstat(8). net.inet6.mld.gsrdelay This variable specifies the time threshold, in seconds, for processing Group-and-Source Specific Queries (GSR). As GSR query pro- cessing requires maintaining state on the host, it may cause memory to be allocated, and is therefore a potential attack point for Denial-of-Service (DoS). If more than one GSR query is received within this threshold, it will be dropped, to mitigate the potential for DoS. net.inet6.mld.v1enable If this variable is non-zero, then MLDv1 membership queries (and host reports) will be processed by this host, and backwards compati- bility will be enabled until the v1 'Older Version Querier Present' timer expires. This sysctl is normally enabled by default. SEE ALSO
ifmcstat(8), inet(4), multicast(4), netstat(1), sourcefilter(3) HISTORY
The mld manual page appeared in FreeBSD 8.0. BSD
May 27, 2009 BSD