Vulnerability Name:

CVE-2004-1951 (CCN-15939)

Assigned:2004-04-22
Published:2004-04-22
Updated:2017-07-11
Summary:xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options in an MRL link.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:File Manipulation
References:Source: MITRE
Type: CNA
CVE-2004-1951

Source: CCN
Type: SA11433
Xine Playlists can Overwrite Arbitrary Files

Source: SECUNIA
Type: UNKNOWN
11433

Source: GENTOO
Type: Patch
GLSA-200404-20

Source: CCN
Type: GLSA-200404-20
Multiple vulnerabilities in xine

Source: CCN
Type: GLSA 200404-20
Multiple vulnerabilities in xine

Source: OSVDB
Type: UNKNOWN
5594

Source: OSVDB
Type: UNKNOWN
5739

Source: CCN
Type: OSVDB ID: 5594
xine-lib Playlists MRL Arbitrary File Modification

Source: CCN
Type: OSVDB ID: 5739
xine-ui Playlists MRL Arbitrary File Modification

Source: BID
Type: Exploit, Patch
10193

Source: CCN
Type: BID-10193
Xine And Xine-Lib Multiple Remote File Overwrite Vulnerabilities

Source: SLACKWARE
Type: UNKNOWN
SSA:2004-111

Source: CCN
Type: xine security announcement XSA-2004-1
xine-lib

Source: CONFIRM
Type: Vendor Advisory
http://www.xinehq.de/index.php/security/XSA-2004-1

Source: CCN
Type: xine security announcement XSA-2004-2
xine-ui

Source: CONFIRM
Type: Vendor Advisory
http://www.xinehq.de/index.php/security/XSA-2004-2

Source: XF
Type: UNKNOWN
xine-mrl-file-overwrite(15939)

Source: XF
Type: UNKNOWN
xine-mrl-file-overwrite(15939)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:xine:xine:0.9.8:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine:0.9.13:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine:1_beta1:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine:1_beta2:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine:1_beta3:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine:1_beta4:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine:1_beta5:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine:1_beta6:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine:1_beta7:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine:1_beta8:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine:1_beta9:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine:1_beta10:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine:1_beta11:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine:1_beta12:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine:1_rc0a:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine:1_rc1:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine:1_rc2:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine:1_rc3:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine:1_rc3a:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine:1_rc3b:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine-lib:1_rc2:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine-lib:1_rc3a:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine-lib:1_rc3b:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine-lib:1_rc3c:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine-ui:0.9.21:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine-ui:0.9.22:*:*:*:*:*:*:*
  • OR cpe:/a:xine:xine-ui:0.9.23:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    xine xine 0.9.8
    xine xine 0.9.13
    xine xine 1_beta1
    xine xine 1_beta2
    xine xine 1_beta3
    xine xine 1_beta4
    xine xine 1_beta5
    xine xine 1_beta6
    xine xine 1_beta7
    xine xine 1_beta8
    xine xine 1_beta9
    xine xine 1_beta10
    xine xine 1_beta11
    xine xine 1_beta12
    xine xine 1_rc0a
    xine xine 1_rc1
    xine xine 1_rc2
    xine xine 1_rc3
    xine xine 1_rc3a
    xine xine 1_rc3b
    xine xine-lib 1_rc2
    xine xine-lib 1_rc3a
    xine xine-lib 1_rc3b
    xine xine-lib 1_rc3c
    xine xine-ui 0.9.21
    xine xine-ui 0.9.22
    xine xine-ui 0.9.23