Oval Definition:oval:org.opensuse.security:def:20085236
Revision Date:2021-08-15Version:1
Title:CVE-2008-5236
Description:

Multiple heap-based buffer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to execute arbitrary code via vectors related to (1) a crafted EBML element length processed by the parse_block_group function in demux_matroska.c; (2) a certain combination of sps, w, and h values processed by the real_parse_audio_specific_data and demux_real_send_chunk functions in demux_real.c; and (3) an unspecified combination of three values processed by the open_ra_file function in demux_realaudio.c. NOTE: vector 2 reportedly exists because of an incomplete fix in 1.1.15.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2008-5236
Mitre CVE-2008-5236
SUSE CVE-2008-5236
SUSE-SR:2009:004
SUSE-SR:2009:004
Platform(s):Novell Linux Desktop 9 for x86
Novell Linux Desktop 9 for x86_64
Novell Linux Desktop 9 SDK for x86
Novell Linux Desktop 9 SDK for x86_64
openSUSE 10.3
openSUSE 11.0
SLES SDK 9 for IBM iSeries and IBM pSeries
SLES SDK 9 for IBM S/390 and IBM zSeries
SLES SDK 9 for IBM zSeries
SLES SDK 9 for IPF
SLES SDK 9 for x86
SLES SDK 9 for X86-64
SUSE Linux Enterprise Desktop 11 SP4
SUSE Linux Enterprise SDK 10 SP2
SUSE Linux Enterprise Server 11 SP4
SUSE Linux Enterprise Server for SAP Applications 11 SP4
SUSE Linux Enterprise Software Development Kit 11 SP4
Product(s):
Definition Synopsis
  • sles10-sp2-sdk is installed
  • AND Package Information
  • xine-devel less than 1.1.1-24.43
  • OR xine-extra less than 1.1.1-24.43
  • OR xine-lib-32bit less than 1.1.1-24.43
  • OR xine-lib-64bit less than 1.1.1-24.43
  • OR xine-lib-x86 less than 1.1.1-24.43
  • OR xine-lib less than 1.1.1-24.43
  • OR xine-ui less than 0.99.4-32.39
  • Definition Synopsis
  • SUSE Linux Enterprise Software Development Kit 11 SP4 is installed
  • AND Package Information
  • libxine-devel-1.1.15-23.3 is installed
  • OR libxine1-1.1.15-23.3 is installed
  • OR libxine1-32bit-1.1.15-23.3 is installed
  • OR libxine1-gnome-vfs-1.1.15-23.3 is installed
  • OR libxine1-pulse-1.1.15-23.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Software Development Kit 11 SP4 is installed
  • AND Package Information
  • libxine-devel-1.1.15-23.3.9 is installed
  • OR libxine1-1.1.15-23.3.9 is installed
  • OR libxine1-32bit-1.1.15-23.3.9 is installed
  • OR libxine1-gnome-vfs-1.1.15-23.3.9 is installed
  • OR libxine1-pulse-1.1.15-23.3.9 is installed
  • BACK