PT-2008-6383 · Xine · Xine-Lib

Will Drewry

·

Publicado

2008-11-26

·

Atualizado

2018-10-11

·

CVE-2008-5241

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions xine-lib versions 1.1.12 and earlier, including 1.1.15 and earlier
Description The issue is related to an integer underflow in the demux qt.c file, which can be triggered by a crafted media file. This results in a denial of service, causing the program to crash. The problem occurs when a compressed MOV file contains a small value of moov atom size, leading to the underflow.
Recommendations For xine-lib versions 1.1.12 and earlier, including 1.1.15 and earlier, update to a version that fixes the integer underflow issue in demux qt.c to prevent denial of service attacks.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-5241

Produtos afetados

Xine-Lib