CVE-2008-0238
published 2008-01-11CVE-2008-0238: Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to execute arbitrary code…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.21%
89.7th percentile
Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to execute arbitrary code via the SDP (1) Title, (2) Author, or (3) Copyright attribute, related to the rmff_dump_header function, different vectors than CVE-2008-0225. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| xine | xine-lib | <= 1.1.9 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_ubuntu6.8MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
xine-lib vulnerabilities
vendor_ubuntu·2008-08-06·CVSS 6.8
CVE-2008-0073 [MEDIUM] xine-lib vulnerabilities
Title: xine-lib vulnerabilities
Summary: xine-lib vulnerabilities
Alin Rad Pop discovered an array index vulnerability in the SDP
parser. If a user or automated system were tricked into opening a
malicious RTSP stream, a remote attacker may be able to execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2008-0073)
Luigi Auriemma discovered that xine-lib did not properly check
buffer sizes in the RTSP header-handling code. If xine-lib opened an
RTSP stream with crafted SDP attributes, a remote attacker may be
able to execute arbitrary code with the privileges of the user
invoking the program. (CVE-2008-0225, CVE-2008-0238)
Damian Frizza and Alfredo Ortega discovered that xine-lib did not
properly validate FLAC tags. If a user or automated system were
tricked
Red Hat
xine-lib: SDP attributes buffer overflow
vendor_redhat·2008-01-09·CVSS 6.4
CVE-2008-0238 [MEDIUM] xine-lib: SDP attributes buffer overflow
xine-lib: SDP attributes buffer overflow
Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to execute arbitrary code via the SDP (1) Title, (2) Author, or (3) Copyright attribute, related to the rmff_dump_header function, different vectors than CVE-2008-0225. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
GHSA
GHSA-m33x-fw9w-58g9: Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff
ghsa_unreviewed·2022-05-01·CVSS 6.4
CVE-2008-0238 [MEDIUM] CWE-119 GHSA-m33x-fw9w-58g9: Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff
Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to execute arbitrary code via the SDP (1) Title, (2) Author, or (3) Copyright attribute, related to the rmff_dump_header function, different vectors than CVE-2008-0225. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
No detection rules found.
No public exploits indexed.
http://bugs.gentoo.org/show_bug.cgi?id=205197http://secunia.com/advisories/28384http://secunia.com/advisories/28674http://secunia.com/advisories/28955http://secunia.com/advisories/31393http://security.gentoo.org/glsa/glsa-200801-12.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:020http://www.mandriva.com/security/advisories?name=MDVSA-2008:045http://www.ubuntu.com/usn/usn-635-1http://bugs.gentoo.org/show_bug.cgi?id=205197http://secunia.com/advisories/28384http://secunia.com/advisories/28674http://secunia.com/advisories/28955http://secunia.com/advisories/31393http://security.gentoo.org/glsa/glsa-200801-12.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:020http://www.mandriva.com/security/advisories?name=MDVSA-2008:045http://www.ubuntu.com/usn/usn-635-1
2008-01-11
Published