Revision Date: | 2021-08-15 | Version: | 1 |
Title: | CVE-2008-5234 |
Description: |
Multiple heap-based buffer overflows in xine-lib 1.1.12, and other versions before 1.1.15, allow remote attackers to execute arbitrary code via vectors related to (1) a crafted metadata atom size processed by the parse_moov_atom function in demux_qt.c and (2) frame reading in the id3v23_interp_frame function in id3.c. NOTE: as of 20081122, it is possible that vector 1 has not been fixed in 1.1.15.
|
Family: | unix | Class: | vulnerability |
Status: | | Reference(s): | CVE-2008-5234 Mitre CVE-2008-5234 SUSE CVE-2008-5234 SUSE-SR:2009:004 SUSE-SR:2009:004
|
Platform(s): | Novell Linux Desktop 9 for x86 Novell Linux Desktop 9 for x86_64 Novell Linux Desktop 9 SDK for x86 Novell Linux Desktop 9 SDK for x86_64 openSUSE 10.3 openSUSE 11.0 SLES SDK 9 for IBM iSeries and IBM pSeries SLES SDK 9 for IBM S/390 and IBM zSeries SLES SDK 9 for IBM zSeries SLES SDK 9 for IPF SLES SDK 9 for x86 SLES SDK 9 for X86-64 SUSE Linux Enterprise Desktop 11 SP4 SUSE Linux Enterprise SDK 10 SP2 SUSE Linux Enterprise Server 11 SP4 SUSE Linux Enterprise Server for SAP Applications 11 SP4 SUSE Linux Enterprise Software Development Kit 11 SP4
| Product(s): | |
Definition Synopsis |
sles10-sp2-sdk is installed AND Package Information
xine-devel less than 1.1.1-24.43
OR xine-extra less than 1.1.1-24.43
OR xine-lib-32bit less than 1.1.1-24.43
OR xine-lib-64bit less than 1.1.1-24.43
OR xine-lib-x86 less than 1.1.1-24.43
OR xine-lib less than 1.1.1-24.43
OR xine-ui less than 0.99.4-32.39
|
Definition Synopsis |
SUSE Linux Enterprise Software Development Kit 11 SP4 is installed
AND Package Information
libxine-devel-1.1.15-23.3 is installed
OR libxine1-1.1.15-23.3 is installed
OR libxine1-32bit-1.1.15-23.3 is installed
OR libxine1-gnome-vfs-1.1.15-23.3 is installed
OR libxine1-pulse-1.1.15-23.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Software Development Kit 11 SP4 is installed
AND Package Information
libxine-devel-1.1.15-23.3.9 is installed
OR libxine1-1.1.15-23.3.9 is installed
OR libxine1-32bit-1.1.15-23.3.9 is installed
OR libxine1-gnome-vfs-1.1.15-23.3.9 is installed
OR libxine1-pulse-1.1.15-23.3.9 is installed
|