PT-2008-6381 · Xine · Xine-Lib

Will Drewry

·

Published

2008-11-26

·

Updated

2018-10-11

·

CVE-2008-5239

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions xine-lib versions 1.1.15 and earlier
Description The issue arises from improper handling of negative and zero values during certain read function calls in various files, including input file.c, input net.c, input smb.c, and input http.c. This can be exploited by remote attackers through vectors such as a file or an HTTP response, potentially leading to a denial of service (crash) or the execution of arbitrary code. The exploitation triggers out-of-bounds reads and heap-based buffer overflows.
Recommendations For xine-lib versions 1.1.15 and earlier, consider updating to a version that properly handles negative and zero values during read function calls to prevent potential denial of service or arbitrary code execution. As a temporary workaround, restrict access to files and HTTP responses that could trigger the vulnerability until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-5239

Affected Products

Xine-Lib