Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-5246

Overview

Vulnerability Score 9.3 9.3
CVE Id CVE-2008-5246
Last Modified 07 Mar 2011 10:14:14
Published 25 Nov 2008 08:30:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-5246

Summary

Multiple heap-based buffer overflows in xine-lib before 1.1.15 allow remote attackers to execute arbitrary code via vectors that send ID3 data to the (1) id3v22_interp_frame and (2) id3v24_interp_frame functions in src/demuxers/id3.c. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Vulnerable Systems

Application

  • Xine-lib 0.9.13

  • Xine-lib 1

  • Xine-lib 1 Beta1

  • Xine-lib 1 Beta10

  • Xine-lib 1 Beta11

  • Xine-lib 1 Beta12

  • Xine-lib 1 Beta2

  • Xine-lib 1 Beta3

  • Xine-lib 1 Beta4

  • Xine-lib 1 Beta5

  • Xine-lib 1 Beta6

  • Xine-lib 1 Beta7

  • Xine-lib 1 Beta8

  • Xine-lib 1 Beta9

  • Xine-lib 1.0

  • Xine-lib 1.0.1

  • Xine-lib 1.0.2

  • Xine-lib 1.0.3a

  • Xine-lib 1.1.0

  • Xine-lib 1.1.1

  • Xine-lib 1.1.10

  • Xine-lib 1.1.10.1

  • Xine-lib 1.1.11

  • Xine-lib 1.1.11.1

  • Xine-lib 1.1.12

  • Xine-lib 1.1.13

  • Xine-lib 1.1.14

  • Xine-lib 1.1.2

  • Xine-lib 1.1.3

  • Xine-lib 1.1.4

  • Xine-lib 1.1.5

  • Xine-lib 1.1.6

  • Xine-lib 1.1.7

  • Xine-lib 1.1.8

  • Xine-lib 1.1.9

  • Xine-lib 1.1.9.1


References

XF - xinelib-srcdemuxersid3-bo(44468)

VUPEN - ADV-2008-2382

BID - 30698

MANDRIVA - MDVSA-2009:020

CONFIRM - http://sourceforge.net/project/shownotes.php?release_id=619869

SECTRACK - 1020703

OSVDB - 47677

SUSE - SUSE-SR:2009:004


Last Updated: 27 May 2016 10:48:46