Upstream information

CVE-2008-0486 at MITRE

Description

Array index vulnerability in libmpdemux/demux_audio.c in MPlayer 1.0rc2 and SVN before r25917, and possibly earlier versions, as used in Xine-lib 1.1.10, might allow remote attackers to execute arbitrary code via a crafted FLAC tag, which triggers a buffer overflow.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having important severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 7.5
Vector AV:N/AC:L/Au:N/C:P/I:P/A:P
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
SUSE Bugzilla entry: 362078 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Software Development Kit 11 SP4
  • libxine-devel >= 1.1.15-23.3.9
  • libxine1 >= 1.1.15-23.3.9
  • libxine1-32bit >= 1.1.15-23.3.9
  • libxine1-gnome-vfs >= 1.1.15-23.3.9
  • libxine1-pulse >= 1.1.15-23.3.9
Patchnames:
SUSE Linux Enterprise Software Development Kit 11 SP4 GA libxine-devel
SUSE LINUX 10.1
  • xine-devel >= 1.1.1-24.29
  • xine-extra >= 1.1.1-24.29
  • xine-lib >= 1.1.1-24.29
  • xine-lib-32bit >= 1.1.1-24.29
  • xine-lib-64bit >= 1.1.1-24.29
  • xine-ui >= 0.99.4-32.25