CVE-2008-5244
published 2008-11-26CVE-2008-5244: Unspecified vulnerability in xine-lib before 1.1.15 has unknown impact and attack vectors related to libfaad. NOTE: due to the lack of details, it is not clear…
PriorityP431critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.01%
78.7th percentile
Unspecified vulnerability in xine-lib before 1.1.15 has unknown impact and attack vectors related to libfaad. NOTE: due to the lack of details, it is not clear whether this is an issue in xine-lib or in libfaad.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | faad2 | < faad2 2.6.1-1 (bookworm) | faad2 2.6.1-1 (bookworm) |
| debian | mplayer | < faad2 2.6.1-1 (bookworm) | faad2 2.6.1-1 (bookworm) |
| faad2_project | faad2 | >= 0 < 2.6.1-1 | 2.6.1-1 |
| faad2_project | faad2 | >= 0 < 2.6.1-1 | 2.6.1-1 |
| faad2_project | faad2 | >= 0 < 2.6.1-1 | 2.6.1-1 |
| faad2_project | faad2 | >= 0 < 2.6.1-1 | 2.6.1-1 |
| mplayer | mplayer | >= 0 < 1.0~rc2-20 | 1.0~rc2-20 |
| mplayer | mplayer | >= 0 < 1.0~rc2-20 | 1.0~rc2-20 |
| mplayer | mplayer | >= 0 < 1.0~rc2-20 | 1.0~rc2-20 |
| mplayer | mplayer | >= 0 < 1.0~rc2-20 | 1.0~rc2-20 |
| xine | xine-lib | <= 1.1.15 | — |
| xine | xine-lib | — | — |
| xine | xine-lib | — | — |
| xine | xine-lib | — | — |
| xine | xine-lib | — | — |
| xine | xine-lib | — | — |
| xine | xine-lib | — | — |
| xine | xine-lib | — | — |
| xine | xine-lib | — | — |
| xine | xine-lib | — | — |
| xine | xine-lib | — | — |
| xine | xine-lib | — | — |
| xine | xine-lib | — | — |
| xine | xine-lib | — | — |
| xine | xine-lib | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0LOW
vendor_redhat9.3CRITICAL
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
xine-lib vulnerabilities
vendor_ubuntu·2009-01-26·CVSS 4.3
CVE-2008-3231 [MEDIUM] xine-lib vulnerabilities
Title: xine-lib vulnerabilities
Summary: xine-lib vulnerabilities
It was discovered that xine-lib did not correctly handle certain malformed
Ogg and Windows Media files. If a user or automated system were tricked into
opening a specially crafted Ogg or Windows Media file, an attacker could cause
xine-lib to crash, creating a denial of service. This issue only applied to
Ubuntu 6.06 LTS, 7.10, and 8.04 LTS. (CVE-2008-3231)
It was discovered that the MNG, MOD, and Real demuxers in xine-lib did not
correctly handle memory allocation failures. If a user or automated system were
tricked into opening a specially crafted MNG, MOD, or Real file, an attacker
could crash xine-lib or possibly execute arbitrary code with the privileges of
the user invoking the program. This issue only applied to Ub
Red Hat
xine-lib: various flaws (CVE-2008-5234 CVE-2008-5235 CVE-2008-5236 CVE-2008-5237 CVE-2008-5239 CVE-2008-5240 CVE-2008-5241 CVE-2008-5242 CVE-2008-5243 CVE-2008-5244 CVE-2008-5247)
vendor_redhat·2008-05-06·CVSS 9.3
CVE-2008-5235 [CRITICAL] xine-lib: various flaws (CVE-2008-5234 CVE-2008-5235 CVE-2008-5236 CVE-2008-5237 CVE-2008-5239 CVE-2008-5240 CVE-2008-5241 CVE-2008-5242 CVE-2008-5243 CVE-2008-5244 CVE-2008-5247)
xine-lib: various flaws (CVE-2008-5234 CVE-2008-5235 CVE-2008-5236 CVE-2008-5237 CVE-2008-5239 CVE-2008-5240 CVE-2008-5241 CVE-2008-5242 CVE-2008-5243 CVE-2008-5244 CVE-2008-5247)
Heap-based buffer overflow in the demux_real_send_chunk function in src/demuxers/demux_real.c in xine-lib before 1.1.15 allows remote attackers to execute arbitrary code via a crafted Real Media file. NOTE: some of these details are obtained from third party information.
Debian
CVE-2008-5244: faad2 - Unspecified vulnerability in xine-lib before 1.1.15 has unknown impact and attac...
vendor_debian·2008·CVSS 10.0
CVE-2008-5244 [CRITICAL] CVE-2008-5244: faad2 - Unspecified vulnerability in xine-lib before 1.1.15 has unknown impact and attac...
Unspecified vulnerability in xine-lib before 1.1.15 has unknown impact and attack vectors related to libfaad. NOTE: due to the lack of details, it is not clear whether this is an issue in xine-lib or in libfaad.
Scope: local
bookworm: resolved (fixed in 2.6.1-1)
bullseye: resolved (fixed in 2.6.1-1)
forky: resolved (fixed in 2.6.1-1)
sid: resolved (fixed in 2.6.1-1)
trixie: resolved (fixed in 2.6.1-1)
GHSA
GHSA-mxx6-w557-j3xm: Unspecified vulnerability in xine-lib before 1
ghsa_unreviewed·2022-05-17
CVE-2008-5244 [HIGH] GHSA-mxx6-w557-j3xm: Unspecified vulnerability in xine-lib before 1
Unspecified vulnerability in xine-lib before 1.1.15 has unknown impact and attack vectors related to libfaad. NOTE: due to the lack of details, it is not clear whether this is an issue in xine-lib or in libfaad.
OSV
CVE-2008-5244: Unspecified vulnerability in xine-lib before 1
osv·2008-11-26·CVSS 10.0
CVE-2008-5244 [CRITICAL] CVE-2008-5244: Unspecified vulnerability in xine-lib before 1
Unspecified vulnerability in xine-lib before 1.1.15 has unknown impact and attack vectors related to libfaad. NOTE: due to the lack of details, it is not clear whether this is an issue in xine-lib or in libfaad.
No detection rules found.
No public exploits indexed.
Bugzilla
xine-lib,gxine,oxine,xine-plugin: CVE-2008-5235 CVE-2008-5236 CVE-2008-5237 CVE-2008-5239 CVE-2008-5240 CVE-2008-5241 CVE-2008-5242 CVE-2008-5243 CVE-2008-5244 CVE-2008-5247 xine-lib various flaws
bugzilla·2008-11-27·CVSS 9.3
CVE-2008-5235 [CRITICAL] xine-lib,gxine,oxine,xine-plugin: CVE-2008-5235 CVE-2008-5236 CVE-2008-5237 CVE-2008-5239 CVE-2008-5240 CVE-2008-5241 CVE-2008-5242 CVE-2008-5243 CVE-2008-5244 CVE-2008-5247 xine-lib various flaws
xine-lib,gxine,oxine,xine-plugin: CVE-2008-5235 CVE-2008-5236 CVE-2008-5237 CVE-2008-5239 CVE-2008-5240 CVE-2008-5241 CVE-2008-5242 CVE-2008-5243 CVE-2008-5244 CVE-2008-5247 xine-lib various flaws
Will Drewry has reported multiple security flaws present in the Xine multimedia
library (NOTE: mentioning only issues that were not addressed in latest upstream
1.1.15 version of the xine-lib library).
References (for more detailed analysis of each issue below proceed to the
following post):
http://www.ocert.org/analysis/2008-008/analysis.txt
CVE-2008-5235:
Heap-based buffer overflow in the demux_real_send_chunk function in
src/demuxers/demux_real.c in xine-lib before 1.1.15 allows remote
attackers to execute arbitrary code via a crafted Real Media file.
NOTE: some of these details are obtai
Bugzilla
xine-lib: various flaws (CVE-2008-5234 CVE-2008-5235 CVE-2008-5236 CVE-2008-5237 CVE-2008-5239 CVE-2008-5240 CVE-2008-5241 CVE-2008-5242 CVE-2008-5243 CVE-2008-5244 CVE-2008-5247)
bugzilla·2008-11-27·CVSS 9.3
CVE-2008-5234 [CRITICAL] xine-lib: various flaws (CVE-2008-5234 CVE-2008-5235 CVE-2008-5236 CVE-2008-5237 CVE-2008-5239 CVE-2008-5240 CVE-2008-5241 CVE-2008-5242 CVE-2008-5243 CVE-2008-5244 CVE-2008-5247)
xine-lib: various flaws (CVE-2008-5234 CVE-2008-5235 CVE-2008-5236 CVE-2008-5237 CVE-2008-5239 CVE-2008-5240 CVE-2008-5241 CVE-2008-5242 CVE-2008-5243 CVE-2008-5244 CVE-2008-5247)
Will Drewry (WD) has reported multiple security flaws present in the Xine multimedia library (NOTE: mentioning only issues that were not addressed in latest upstream 1.1.15 version of the xine-lib library).
References (for more detailed analysis of each issue below proceed to the
following post):
http://www.ocert.org/analysis/2008-008/analysis.txt
CVE-2008-5235:
Heap-based buffer overflow in the demux_real_send_chunk function in
src/demuxers/demux_real.c in xine-lib before 1.1.15 allows remote
attackers to execute arbitrary code via a crafted Real Media file.
NOTE: some of these details are obtained from thi
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.htmlhttp://securitytracker.com/id?1020703http://sourceforge.net/project/shownotes.php?release_id=619869http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.htmlhttp://securitytracker.com/id?1020703http://sourceforge.net/project/shownotes.php?release_id=619869
2008-11-26
Published