Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2008-1482

Published: 24 March 2008

Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrary code via (1) a crafted .FLV file, which triggers an overflow in demuxers/demux_flv.c; (2) a crafted .MOV file, which triggers an overflow in demuxers/demux_qt.c; (3) a crafted .RM file, which triggers an overflow in demuxers/demux_real.c; (4) a crafted .MVE file, which triggers an overflow in demuxers/demux_wc3movie.c; (5) a crafted .MKV file, which triggers an overflow in demuxers/ebml.c; or (6) a crafted .CAK file, which triggers an overflow in demuxers/demux_film.c.

Notes

AuthorNote
jdstrand
FLV on dapper not affected as vulnerable code not present

Priority

Medium

Status

Package Release Status
xine-lib
Launchpad, Ubuntu, Debian
dapper
Released (1.1.1+ubuntu2-7.9)
edgy Ignored
(end of life, was needed)
feisty
Released (1.1.4-2ubuntu3.1)
gutsy
Released (1.1.7-1ubuntu1.3)
hardy Not vulnerable
(1.1.11.1-1ubuntu3)
upstream
Released (1.1.11.1-1)
Patches:
vendor: http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:046
vendor: http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:046-1
vendor: http://hg.debian.org/hg/xine-lib/xine-lib?cmd=changeset;node=a3f2772fd14b57e0557ef45797ff04c768657a7e;style=gitweb