PT-2004-2848 · Xine · Xine+1
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-1951
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
xine versions 1.x alpha through 1.0rc3a
xine-ui versions 0.9.21 through 0.9.23
Description
The issue allows remote attackers to overwrite arbitrary files via specific options in an MRL link, including the
audio.sun audio device or dxr3.devicename options.Recommendations
For xine versions 1.x alpha through 1.0rc3a, avoid using the
audio.sun audio device and dxr3.devicename options in MRL links until a fix is available.
For xine-ui versions 0.9.21 through 0.9.23, restrict the use of the audio.sun audio device and dxr3.devicename options in MRL links to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xine
Xine-Ui