CVE-2008-1110
published 2008-02-29CVE-2008-1110: Buffer overflow in demuxers/demux_asf.c (aka the ASF demuxer) in the xineplug_dmx_asf.so plugin in xine-lib before 1.1.10 allows remote attackers to execute…
PriorityP341medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EXPLOIT
EPSS
10.37%
95.2th percentile
Buffer overflow in demuxers/demux_asf.c (aka the ASF demuxer) in the xineplug_dmx_asf.so plugin in xine-lib before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted ASF header. NOTE: this issue leads to a crash when an attack uses the CVE-2006-1664 exploit code, but it is different from CVE-2006-1664.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| xine | xine-lib | <= 1.1.9 | — |
| xine | xine-plugin | <= 1.1.9 | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_ubuntu6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
xine-lib vulnerabilities
vendor_ubuntu·2008-08-06·CVSS 6.8
CVE-2008-0073 [MEDIUM] xine-lib vulnerabilities
Title: xine-lib vulnerabilities
Summary: xine-lib vulnerabilities
Alin Rad Pop discovered an array index vulnerability in the SDP
parser. If a user or automated system were tricked into opening a
malicious RTSP stream, a remote attacker may be able to execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2008-0073)
Luigi Auriemma discovered that xine-lib did not properly check
buffer sizes in the RTSP header-handling code. If xine-lib opened an
RTSP stream with crafted SDP attributes, a remote attacker may be
able to execute arbitrary code with the privileges of the user
invoking the program. (CVE-2008-0225, CVE-2008-0238)
Damian Frizza and Alfredo Ortega discovered that xine-lib did not
properly validate FLAC tags. If a user or automated system were
tricked
GHSA
GHSA-fccg-vfm7-whwm: Buffer overflow in demuxers/demux_asf
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2008-1110 [HIGH] CWE-119 GHSA-fccg-vfm7-whwm: Buffer overflow in demuxers/demux_asf
Buffer overflow in demuxers/demux_asf.c (aka the ASF demuxer) in the xineplug_dmx_asf.so plugin in xine-lib before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted ASF header. NOTE: this issue leads to a crash when an attack uses the CVE-2006-1664 exploit code, but it is different from CVE-2006-1664.
No detection rules found.
No writeups or analysis indexed.
http://bugs.gentoo.org/show_bug.cgi?id=208100http://hg.debian.org/hg/xine-lib/xine-lib?cmd=changeset%3Bnode=fb6d089b520dca199ef16a046da28c50c984c2d2%3Bstyle=gitwebhttp://secunia.com/advisories/29141http://secunia.com/advisories/31393http://security.gentoo.org/glsa/glsa-200802-12.xmlhttp://sourceforge.net/project/shownotes.php?group_id=9655&release_id=571608http://www.mandriva.com/security/advisories?name=MDVSA-2008:178http://www.ubuntu.com/usn/usn-635-1http://xinehq.de/index.php/newshttp://xinehq.de/index.php/securityhttps://exchange.xforce.ibmcloud.com/vulnerabilities/41019https://www.exploit-db.com/exploits/1641http://bugs.gentoo.org/show_bug.cgi?id=208100http://hg.debian.org/hg/xine-lib/xine-lib?cmd=changeset%3Bnode=fb6d089b520dca199ef16a046da28c50c984c2d2%3Bstyle=gitwebhttp://secunia.com/advisories/29141http://secunia.com/advisories/31393http://security.gentoo.org/glsa/glsa-200802-12.xmlhttp://sourceforge.net/project/shownotes.php?group_id=9655&release_id=571608http://www.mandriva.com/security/advisories?name=MDVSA-2008:178http://www.ubuntu.com/usn/usn-635-1http://xinehq.de/index.php/newshttp://xinehq.de/index.php/securityhttps://exchange.xforce.ibmcloud.com/vulnerabilities/41019https://www.exploit-db.com/exploits/1641
2008-02-29
Published