PT-2008-6381 · Xine · Xine-Lib
Will Drewry
·
Published
2008-11-26
·
Updated
2018-10-11
·
CVE-2008-5239
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
xine-lib versions 1.1.15 and earlier
Description
The issue arises from improper handling of negative and zero values during certain read function calls in various files, including input file.c, input net.c, input smb.c, and input http.c. This can be exploited by remote attackers through vectors such as a file or an HTTP response, potentially leading to a denial of service (crash) or the execution of arbitrary code. The exploitation triggers out-of-bounds reads and heap-based buffer overflows.
Recommendations
For xine-lib versions 1.1.15 and earlier, consider updating to a version that properly handles negative and zero values during read function calls to prevent potential denial of service or arbitrary code execution. As a temporary workaround, restrict access to files and HTTP responses that could trigger the vulnerability until a patch is available.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xine-Lib