Vulnerability Name: | CVE-2005-2967 (CCN-22545) | ||||||||||||
Assigned: | 2005-10-10 | ||||||||||||
Published: | 2005-10-10 | ||||||||||||
Updated: | 2017-07-11 | ||||||||||||
Summary: | Format string vulnerability in input_cdda.c in xine-lib 1-beta through 1-beta 3, 1-rc, 1.0 through 1.0.2, and 1.1.1 allows remote servers to execute arbitrary code via format string specifiers in metadata in CDDB server responses when the victim plays a CD. | ||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: FULLDISC Type: UNKNOWN 20051008 xine/gxine CD Player Remote Format String Bug Source: MITRE Type: CNA CVE-2005-2967 Source: SECUNIA Type: UNKNOWN 17097 Source: CCN Type: SA17099 xine-lib CDDB Client Format String Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 17099 Source: SECUNIA Type: UNKNOWN 17111 Source: SECUNIA Type: UNKNOWN 17132 Source: SECUNIA Type: UNKNOWN 17162 Source: SECUNIA Type: UNKNOWN 17179 Source: SECUNIA Type: UNKNOWN 17282 Source: SLACKWARE Type: UNKNOWN SSA:2005-283-01 Source: DEBIAN Type: Patch, Vendor Advisory DSA-863 Source: DEBIAN Type: DSA-863 xine-lib -- format string vulnerability Source: CCN Type: GLSA-200510-08 xine-lib: Format string vulnerability Source: GENTOO Type: Vendor Advisory GLSA-200510-08 Source: MANDRIVA Type: UNKNOWN MDKSA-2005:180 Source: SUSE Type: UNKNOWN SUSE-SR:2005:024 Source: OSVDB Type: UNKNOWN 19892 Source: CCN Type: OSVDB ID: 19892 xine/gxine xine-lib CDDB Response Format String Source: BID Type: Exploit, Patch 15044 Source: CCN Type: BID-15044 Xine-Lib Remote CDDB Information Format String Vulnerability Source: CCN Type: USN-196-1 Xine library vulnerability Source: UBUNTU Type: UNKNOWN USN-196-1 Source: CCN Type: xine Web site xine - A Free Video Player Source: CCN Type: xine Download Web page Download and install xine-lib Source: CCN Type: xine security announcement XSA-2005-1 Announcement-ID: XSA-2005-1 Source: CONFIRM Type: Patch, Vendor Advisory http://xinehq.de/index.php/security/XSA-2005-1 Source: XF Type: UNKNOWN xinelib-inputcdda-format-string(22545) Source: XF Type: UNKNOWN xinelib-inputcdda-format-string(22545) Source: SUSE Type: SUSE-SR:2005:024 SUSE Security Summary Report | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |