CVE-2008-0225
published 2008-01-10CVE-2008-0225: Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary…
PriorityP343medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EXPLOIT
EPSS
14.97%
96.3th percentile
Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary code via the SDP Abstract attribute in an RTSP session, related to the rmff_dump_header function and related to disregarding the max field. NOTE: some of these details are obtained from third party information.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| xine | xine-lib | <= 1.1.9 | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_redhat10.0CRITICAL
vendor_ubuntu6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
xine-lib vulnerabilities
vendor_ubuntu·2008-08-06·CVSS 6.8
CVE-2008-0073 [MEDIUM] xine-lib vulnerabilities
Title: xine-lib vulnerabilities
Summary: xine-lib vulnerabilities
Alin Rad Pop discovered an array index vulnerability in the SDP
parser. If a user or automated system were tricked into opening a
malicious RTSP stream, a remote attacker may be able to execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2008-0073)
Luigi Auriemma discovered that xine-lib did not properly check
buffer sizes in the RTSP header-handling code. If xine-lib opened an
RTSP stream with crafted SDP attributes, a remote attacker may be
able to execute arbitrary code with the privileges of the user
invoking the program. (CVE-2008-0225, CVE-2008-0238)
Damian Frizza and Alfredo Ortega discovered that xine-lib did not
properly validate FLAC tags. If a user or automated system were
tricked
Red Hat
kernel: uvcvideo: Fix a buffer overflow in format descriptor parsing
vendor_redhat·2008-07-31·CVSS 10.0
CVE-2008-3496 [CRITICAL] kernel: uvcvideo: Fix a buffer overflow in format descriptor parsing
kernel: uvcvideo: Fix a buffer overflow in format descriptor parsing
Buffer overflow in format descriptor parsing in the uvc_parse_format function in drivers/media/video/uvc/uvc_driver.c in uvcvideo in the video4linux (V4L) implementation in the Linux kernel before 2.6.26.1 has unknown impact and attack vectors.
Statement: Not vulnerable. This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, 5 or Red Hat Enterprise MRG.
The uvcvideo driver was first added in kernel packages update RHSA-2009:0225 in Red Hat Enterprise Linux 5.3, and it already contained a fix for this flaw.
Red Hat
xine-lib: SDP attributes buffer overflow
vendor_redhat·2008-01-09·CVSS 6.4
CVE-2008-0238 [MEDIUM] xine-lib: SDP attributes buffer overflow
xine-lib: SDP attributes buffer overflow
Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to execute arbitrary code via the SDP (1) Title, (2) Author, or (3) Copyright attribute, related to the rmff_dump_header function, different vectors than CVE-2008-0225. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Red Hat
xine-lib: SDP attributes buffer overflow
vendor_redhat·2008-01-08·CVSS 6.4
CVE-2008-0225 [MEDIUM] xine-lib: SDP attributes buffer overflow
xine-lib: SDP attributes buffer overflow
Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary code via the SDP Abstract attribute in an RTSP session, related to the rmff_dump_header function and related to disregarding the max field. NOTE: some of these details are obtained from third party information.
GHSA
GHSA-m33x-fw9w-58g9: Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff
ghsa_unreviewed·2022-05-01·CVSS 6.4
CVE-2008-0238 [MEDIUM] CWE-119 GHSA-m33x-fw9w-58g9: Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff
Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to execute arbitrary code via the SDP (1) Title, (2) Author, or (3) Copyright attribute, related to the rmff_dump_header function, different vectors than CVE-2008-0225. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
GHSA
GHSA-552c-gjq7-88rp: Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff
ghsa_unreviewed·2022-05-01
CVE-2008-0225 [MEDIUM] CWE-119 GHSA-552c-gjq7-88rp: Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff
Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary code via the SDP Abstract attribute in an RTSP session, related to the rmff_dump_header function and related to disregarding the max field. NOTE: some of these details are obtained from third party information.
No detection rules found.
Bugzilla
CVE-2008-0238 xine-lib: SDP attributes buffer overflow
bugzilla·2008-01-14·CVSS 6.4
CVE-2008-0238 [MEDIUM] CVE-2008-0238 xine-lib: SDP attributes buffer overflow
CVE-2008-0238 xine-lib: SDP attributes buffer overflow
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-0238 to the following vulnerability:
Multiple heap-based buffer overflows in the rmff_dump_cont function in
input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to
execute arbitrary code via the SDP (1) Title, (2) Author, or (3)
Copyright attribute, related to the rmff_dump_header function,
different vectors than CVE-2008-0225. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
References:
http://secunia.com/advisories/28384
Discussion:
Upstream fix in 1.1.9.1 seems to address these additional vectors too. xine-lib
maintainers, what do you think?
---
Upstream confirms that this is fixed in
Bugzilla
CVE-2008-0225 xine-lib: SDP attributes buffer overflow
bugzilla·2008-01-14·CVSS 6.4
CVE-2008-0225 [MEDIUM] CVE-2008-0225 xine-lib: SDP attributes buffer overflow
CVE-2008-0225 xine-lib: SDP attributes buffer overflow
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-0225 to the following vulnerability:
Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary code via the SDP Abstract attribute, related to the rmff_dump_header function and related to disregarding the max field. NOTE: some of these details are obtained from third party information.
References:
http://aluigi.altervista.org/adv/xinermffhof-adv.txt
http://secunia.com/advisories/28384
Discussion:
This issue was addressed in upstream version 1.1.9.1:
http://sourceforge.net/project/shownotes.php?release_id=567872&group_id=9655
Updates to F7 and F8 are pending appro
http://aluigi.altervista.org/adv/xinermffhof-adv.txthttp://bugs.gentoo.org/show_bug.cgi?id=205197http://secunia.com/advisories/28384http://secunia.com/advisories/28489http://secunia.com/advisories/28507http://secunia.com/advisories/28636http://secunia.com/advisories/28674http://secunia.com/advisories/28955http://secunia.com/advisories/31393http://security.gentoo.org/glsa/glsa-200801-12.xmlhttp://sourceforge.net/project/shownotes.php?release_id=567872http://www.debian.org/security/2008/dsa-1472http://www.mandriva.com/security/advisories?name=MDVSA-2008:020http://www.mandriva.com/security/advisories?name=MDVSA-2008:045http://www.novell.com/linux/security/advisories/suse_security_summary_report.htmlhttp://www.securityfocus.com/bid/27198http://www.ubuntu.com/usn/usn-635-1http://www.vupen.com/english/advisories/2008/0163https://bugzilla.redhat.com/show_bug.cgi?id=428620https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00592.htmlhttp://aluigi.altervista.org/adv/xinermffhof-adv.txthttp://bugs.gentoo.org/show_bug.cgi?id=205197http://secunia.com/advisories/28384http://secunia.com/advisories/28489http://secunia.com/advisories/28507http://secunia.com/advisories/28636http://secunia.com/advisories/28674http://secunia.com/advisories/28955http://secunia.com/advisories/31393http://security.gentoo.org/glsa/glsa-200801-12.xmlhttp://sourceforge.net/project/shownotes.php?release_id=567872http://www.debian.org/security/2008/dsa-1472http://www.mandriva.com/security/advisories?name=MDVSA-2008:020http://www.mandriva.com/security/advisories?name=MDVSA-2008:045http://www.novell.com/linux/security/advisories/suse_security_summary_report.htmlhttp://www.securityfocus.com/bid/27198http://www.ubuntu.com/usn/usn-635-1http://www.vupen.com/english/advisories/2008/0163https://bugzilla.redhat.com/show_bug.cgi?id=428620https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00592.html
2008-01-10
Published