CVE-2009-1274
Published: 8 April 2009
Integer overflow in the qt_error parse_trak_atom function in demuxers/demux_qt.c in xine-lib 1.1.16.2 and earlier allows remote attackers to execute arbitrary code via a Quicktime movie file with a large count value in an STTS atom, which triggers a heap-based buffer overflow.
Notes
Author | Note |
---|---|
mdeslaur | when fixing this, need to also fix a missing part of CVE-2009-0698 http://hg.debian.org/hg/xine-lib/xine-lib/rev/7799748cc0f2 |
Priority
Status
Package | Release | Status |
---|---|---|
xine-lib Launchpad, Ubuntu, Debian |
upstream |
Needs triage
|
dapper |
Released
(1.1.1+ubuntu2-7.12)
|
|
gutsy |
Ignored
(end of life, was needs-triage)
|
|
hardy |
Released
(1.1.11.1-1ubuntu3.4)
|
|
intrepid |
Released
(1.1.15-0ubuntu3.3)
|
|
Patches: upstream: http://hg.debian.org/hg/xine-lib/xine-lib/rev/d21a4564db03 |