CVE-2008-1878

Publication date 17 April 2008

Last updated 24 July 2024


Ubuntu priority

Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long NSF title.

Read the notes from the security team

Status

Package Ubuntu Release Status
xine-lib 8.04 LTS hardy
Fixed 1.1.11.1-1ubuntu3.1
7.10 gutsy
Fixed 1.1.7-1ubuntu1.3
7.04 feisty
Fixed 1.1.4-2ubuntu3.1
6.06 LTS dapper
Fixed 1.1.1+ubuntu2-7.9

Notes


jdstrand

PoC http://www.milw0rm.com/exploits/5458

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
xine-lib

References

Related Ubuntu Security Notices (USN)

    • USN-635-1
    • xine-lib vulnerabilities
    • 6 August 2008

Other references