Language Selection

English French German Italian Portuguese Spanish

Security Flaws Found in Mplayer and Elm

Filed under
Security

Two serious security flaws have turned up in software widely distributed with Linux and Unix. The bugs affect Electronic Mail for Unix (Elm), a venerable e-mail client still used by many Linux and Unix systems administrators, and Mplayer, a cross-platform movie player that is one of the most popular of its kind on Linux.

The Elm flaw involves a boundary error when the client reads an e-mail's "Expires" header. A specially crafted e-mail could exploit the bug to cause a buffer overflow and execute malicious code on a system, according to security researchers.

The bug in Mplayer is the latest media-player bug to plague systems administrators. Widely used desktop applications such as media players are more difficult to patch than server-side bugs, because there are many times more copies in use, often without the knowledge of IT managers.

The flaw affects Mplayer versions 1.0pre7 and earlier and hasn't been patched, according to an advisory from FrSIRT.

Full Story.

More in Tux Machines

World’s smallest i.MX6 module has onboard WiFi, eMMC

Variscite unveiled a 50 x 20mm “DART-MX6″ module that runs Linux or Android on the Freescale i.MX6, with up to 64GB eMMC flash and -40 to 85°C support. Variscite’s claim that the 50 x 20mm DART-MX6 is the world’s smallest computer-on-module based on Freescale’s i.MX6 system-on-chip appears to be a valid one. It beats the smallest ones we’ve seen to date: TechNexion’s 40 x 36mm PICO-IMX6, and Solid-Run’s 47 x 30mm microSOM i4. It’s also just a hair larger than Variscite’s own 52 x 17mm DART-4460, which is based on a dual-core TI OMAP4460 SoC, and Gumstix’s slightly larger 58 x 17mm Overo modules, which use TI Sitara AM37xx SoCs. Read more

BQ Aquaris E4.5 Ubuntu Edition review

The BQ Aquaris e4.5 Ubuntu Edition is not the debut Canonical must have envisaged for Ubuntu Phone, in the early days of the platform’s development. It’s a perfectly functional smartphone for the most part, and we like the concept of scopes, but the hardware is humdrum, performance is sluggish, and the software running on it is rough and ready, and full of holes. We’ll be tracking the progress of Ubuntu Phone with interest – it surely must get better than this – but this first device is one to write off to experience. Read more