CVE-2008-1482
published 2008-03-24CVE-2008-1482: Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrary code via…
PriorityP341medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EXPLOIT
EPSS
9.54%
94.8th percentile
Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrary code via (1) a crafted .FLV file, which triggers an overflow in demuxers/demux_flv.c; (2) a crafted .MOV file, which triggers an overflow in demuxers/demux_qt.c; (3) a crafted .RM file, which triggers an overflow in demuxers/demux_real.c; (4) a crafted .MVE file, which triggers an overflow in demuxers/demux_wc3movie.c; (5) a crafted .MKV file, which triggers an overflow in demuxers/ebml.c; or (6) a crafted .CAK file, which triggers an overflow in demuxers/demux_film.c.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| xine | xine-lib | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
xine-lib vulnerabilities
vendor_ubuntu·2008-08-06·CVSS 6.8
CVE-2008-0073 [MEDIUM] xine-lib vulnerabilities
Title: xine-lib vulnerabilities
Summary: xine-lib vulnerabilities
Alin Rad Pop discovered an array index vulnerability in the SDP
parser. If a user or automated system were tricked into opening a
malicious RTSP stream, a remote attacker may be able to execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2008-0073)
Luigi Auriemma discovered that xine-lib did not properly check
buffer sizes in the RTSP header-handling code. If xine-lib opened an
RTSP stream with crafted SDP attributes, a remote attacker may be
able to execute arbitrary code with the privileges of the user
invoking the program. (CVE-2008-0225, CVE-2008-0238)
Damian Frizza and Alfredo Ortega discovered that xine-lib did not
properly validate FLAC tags. If a user or automated system were
tricked
Red Hat
xine-lib Integer overflow flaws
vendor_redhat·CVSS 6.8
CVE-2008-1482 [MEDIUM] xine-lib Integer overflow flaws
xine-lib Integer overflow flaws
Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrary code via (1) a crafted .FLV file, which triggers an overflow in demuxers/demux_flv.c; (2) a crafted .MOV file, which triggers an overflow in demuxers/demux_qt.c; (3) a crafted .RM file, which triggers an overflow in demuxers/demux_real.c; (4) a crafted .MVE file, which triggers an overflow in demuxers/demux_wc3movie.c; (5) a crafted .MKV file, which triggers an overflow in demuxers/ebml.c; or (6) a crafted .CAK file, which triggers an overflow in demuxers/demux_film.c.
GHSA
GHSA-7vf8-639x-9hxv: Multiple integer overflows in xine-lib 1
ghsa_unreviewed·2022-05-01
CVE-2008-1482 [MEDIUM] CWE-119 GHSA-7vf8-639x-9hxv: Multiple integer overflows in xine-lib 1
Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrary code via (1) a crafted .FLV file, which triggers an overflow in demuxers/demux_flv.c; (2) a crafted .MOV file, which triggers an overflow in demuxers/demux_qt.c; (3) a crafted .RM file, which triggers an overflow in demuxers/demux_real.c; (4) a crafted .MVE file, which triggers an overflow in demuxers/demux_wc3movie.c; (5) a crafted .MKV file, which triggers an overflow in demuxers/ebml.c; or (6) a crafted .CAK file, which triggers an overflow in demuxers/demux_film.c.
No detection rules found.
http://aluigi.altervista.org/adv/xinehof-adv.txthttp://aluigi.org/poc/xinehof.ziphttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.htmlhttp://secunia.com/advisories/29484http://secunia.com/advisories/29600http://secunia.com/advisories/29622http://secunia.com/advisories/29740http://secunia.com/advisories/29756http://secunia.com/advisories/30337http://secunia.com/advisories/31372http://secunia.com/advisories/31393http://security.gentoo.org/glsa/glsa-200808-01.xmlhttp://securityreason.com/securityalert/3769http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.441137http://www.debian.org/security/2008/dsa-1586http://www.mandriva.com/security/advisories?name=MDVSA-2008:178http://www.securityfocus.com/archive/1/489894/100/0/threadedhttp://www.securityfocus.com/bid/28370http://www.ubuntu.com/usn/usn-635-1http://www.vupen.com/english/advisories/2008/0981/referenceshttps://bugzilla.redhat.com/show_bug.cgi?id=438663https://exchange.xforce.ibmcloud.com/vulnerabilities/41350https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00143.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-April/msg00157.htmlhttp://aluigi.altervista.org/adv/xinehof-adv.txthttp://aluigi.org/poc/xinehof.ziphttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.htmlhttp://secunia.com/advisories/29484http://secunia.com/advisories/29600http://secunia.com/advisories/29622http://secunia.com/advisories/29740http://secunia.com/advisories/29756http://secunia.com/advisories/30337http://secunia.com/advisories/31372http://secunia.com/advisories/31393http://security.gentoo.org/glsa/glsa-200808-01.xmlhttp://securityreason.com/securityalert/3769http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.441137http://www.debian.org/security/2008/dsa-1586http://www.mandriva.com/security/advisories?name=MDVSA-2008:178http://www.securityfocus.com/archive/1/489894/100/0/threadedhttp://www.securityfocus.com/bid/28370http://www.ubuntu.com/usn/usn-635-1http://www.vupen.com/english/advisories/2008/0981/referenceshttps://bugzilla.redhat.com/show_bug.cgi?id=438663https://exchange.xforce.ibmcloud.com/vulnerabilities/41350https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00143.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-April/msg00157.html
2008-03-24
Published