CVE Database
/

CVE-2008-1482

Back to search

CVE-2008-1482

Published: Mar 24, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrary code via (1) a crafted .FLV file, which triggers an overflow in demuxers/demux_flv.c; (2) a crafted .MOV file, which triggers an overflow in demuxers/demux_qt.c; (3) a crafted .RM file, which triggers an overflow in demuxers/demux_real.c; (4) a crafted .MVE file, which triggers an overflow in demuxers/demux_wc3movie.c; (5) a crafted .MKV file, which triggers an overflow in demuxers/ebml.c; or (6) a crafted .CAK file, which triggers an overflow in demuxers/demux_film.c.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2008-0981
vdb-entry
x_refsource_VUPEN
29622
third-party-advisory
x_refsource_SECUNIA
GLSA-200808-01
vendor-advisory
x_refsource_GENTOO
SUSE-SR:2008:008
vendor-advisory
x_refsource_SUSE
3769
third-party-advisory
x_refsource_SREASON
DSA-1586
vendor-advisory
x_refsource_DEBIAN
FEDORA-2008-2945
vendor-advisory
x_refsource_FEDORA
29484
third-party-advisory
x_refsource_SECUNIA
29756
third-party-advisory
x_refsource_SECUNIA
29600
third-party-advisory
x_refsource_SECUNIA
29740
third-party-advisory
x_refsource_SECUNIA
31393
third-party-advisory
x_refsource_SECUNIA
MDVSA-2008:178
vendor-advisory
x_refsource_MANDRIVA
xinelib-multiple-bo(41350)
vdb-entry
x_refsource_XF
FEDORA-2008-2849
vendor-advisory
x_refsource_FEDORA
SSA:2008-092-01
vendor-advisory
x_refsource_SLACKWARE
28370
vdb-entry
x_refsource_BID
31372
third-party-advisory
x_refsource_SECUNIA
USN-635-1
vendor-advisory
x_refsource_UBUNTU
30337
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now