CVE-2008-0238
Published: 11 January 2008
Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to execute arbitrary code via the SDP (1) Title, (2) Author, or (3) Copyright attribute, related to the rmff_dump_header function, different vectors than CVE-2008-0225. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Priority
Status
Package | Release | Status |
---|---|---|
mplayer Launchpad, Ubuntu, Debian |
dapper |
Released
(2:0.99+1.0pre7try2+cvs20060117-0ubuntu8.2)
|
edgy |
Released
(2:0.99+1.0pre8-0ubuntu8.3)
|
|
feisty |
Released
(2:1.0~rc1-0ubuntu9.3)
|
|
gutsy |
Released
(2:1.0~rc1-0ubuntu13.2)
|
|
hardy |
Not vulnerable
|
|
upstream |
Not vulnerable
|
|
Patches: vendor: http://www.mandriva.com/security/advisories?name=MDVSA-2008:020 |
||
xine-lib Launchpad, Ubuntu, Debian |
dapper |
Released
(1.1.1+ubuntu2-7.9)
|
edgy |
Ignored
(end of life, was needed)
|
|
feisty |
Released
(1.1.4-2ubuntu3.1)
|
|
gutsy |
Released
(1.1.7-1ubuntu1.3)
|
|
hardy |
Not vulnerable
(1.1.11.1-1ubuntu3)
|
|
upstream |
Released
(1.1.9.1)
|