DescriptionMultiple heap-based buffer overflows in xine-lib 1.1.12, and other versions before 1.1.15, allow remote attackers to execute arbitrary code via vectors related to (1) a crafted metadata atom size processed by the parse_moov_atom function in demux_qt.c and (2) frame reading in the id3v23_interp_frame function in id3.c. NOTE: as of 20081122, it is possible that vector 1 has not been fixed in 1.1.15.
Overall state of this security issue: Resolved
This issue is currently rated as having critical severity.
|National Vulnerability Database|
SUSE Security Advisories:
- SUSE-SR:2009:004, published Tue, 17 Feb 2009 10:00:00 +0000
List of released packages
|Product(s)||Fixed package version(s)||References|
|SUSE Linux Enterprise Desktop 11 SP4 |
SUSE Linux Enterprise Server 11 SP4
SUSE Linux Enterprise Server for SAP Applications 11 SP4
SUSE Linux Enterprise Software Development Kit 11 SP4
| ||Patchnames: |
SUSE Linux Enterprise Software Development Kit 11 SP4 GA libxine-devel-1.1.15-23.3.9
SUSE Timeline for this CVECVE page created: Fri Jun 28 06:38:33 2013
CVE page last modified: Fri Oct 7 12:45:43 2022