10

CVE-2008-5237

Multiple integer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) crafted width and height values that are not validated by the mymng_process_header function in demux_mng.c before use in an allocation calculation or (2) crafted current_atom_size and string_size values processed by the parse_reference_atom function in demux_qt.c for an RDRF_ATOM string.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xine ≫ Xine Version <= 1.1.5
Xine ≫ Xine Version 0.9.13
Xine ≫ Xine Version 1 Update beta1
Xine ≫ Xine Version 1 Update beta10
Xine ≫ Xine Version 1 Update beta11
Xine ≫ Xine Version 1 Update beta12
Xine ≫ Xine Version 1 Update beta2
Xine ≫ Xine Version 1 Update beta3
Xine ≫ Xine Version 1 Update beta4
Xine ≫ Xine Version 1 Update beta5
Xine ≫ Xine Version 1 Update beta6
Xine ≫ Xine Version 1 Update beta7
Xine ≫ Xine Version 1 Update beta8
Xine ≫ Xine Version 1 Update beta9
Xine ≫ Xine Version 1 Update rc0a
Xine ≫ Xine Version 1 Update rc1
Xine ≫ Xine Version 1 Update rc2
Xine ≫ Xine Version 1 Update rc3
Xine ≫ Xine Version 1 Update rc3a
Xine ≫ Xine Version 1 Update rc3b
Xine ≫ Xine Version 1 Update rc3c
Xine ≫ Xine Version 1 Update rc4
Xine ≫ Xine Version 1 Update rc4a
Xine ≫ Xine Version 1 Update rc5
Xine ≫ Xine Version 1 Update rc6a
Xine ≫ Xine Version 1 Update rc7
Xine ≫ Xine Version 1 Update rc8
Xine ≫ Xine Version 1.0
Xine ≫ Xine Version 1.0.1
Xine ≫ Xine Version 1.0.2
Xine ≫ Xine Version 1.0.3a
Xine ≫ Xine Version 1.1.0
Xine ≫ Xine Version 1.1.1
Xine ≫ Xine Version 1.1.2
Xine ≫ Xine Version 1.1.3
Xine ≫ Xine Version 1.1.4
Xine ≫ Xine Version 1.1.10.1
Xine ≫ Xine Version 1.1.11
Xine ≫ Xine Version 1.1.11.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.55% 0.918
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
http://secunia.com/advisories/31827
http://www.mandriva.com/security/advisories?name=MDVSA-2009:020
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00174.html
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00385.html
http://securityreason.com/securityalert/4648
http://www.ocert.org/analysis/2008-008/analysis.txt
http://www.securityfocus.com/archive/1/495674/100/0/threaded
http://www.securityfocus.com/bid/30797
http://secunia.com/advisories/33544
https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00555.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/44652