Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2009-1274

Published: 8 April 2009

Integer overflow in the qt_error parse_trak_atom function in demuxers/demux_qt.c in xine-lib 1.1.16.2 and earlier allows remote attackers to execute arbitrary code via a Quicktime movie file with a large count value in an STTS atom, which triggers a heap-based buffer overflow.

Notes

AuthorNote
mdeslaur
when fixing this, need to also fix a missing part of CVE-2009-0698
http://hg.debian.org/hg/xine-lib/xine-lib/rev/7799748cc0f2

Priority

Medium

Status

Package Release Status
xine-lib
Launchpad, Ubuntu, Debian
upstream Needs triage

dapper
Released (1.1.1+ubuntu2-7.12)
gutsy Ignored
(end of life, was needs-triage)
hardy
Released (1.1.11.1-1ubuntu3.4)
intrepid
Released (1.1.15-0ubuntu3.3)
Patches:
upstream: http://hg.debian.org/hg/xine-lib/xine-lib/rev/d21a4564db03