PT-2008-6389 · Xine · Xine-Lib

Will Drewry

·

Published

2008-11-26

·

Updated

2018-10-11

·

CVE-2008-5247

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions xine-lib versions 1.1.12 through 1.1.15
Description The issue concerns the real parse audio specific data function in demux real.c, which uses an untrusted height value, also referred to as codec data length, as a divisor. This allows remote attackers to cause a denial of service by triggering a divide-by-zero error and crash via a zero value.
Recommendations For xine-lib versions 1.1.12 through 1.1.15, consider applying a patch that checks for and handles the zero value in the real parse audio specific data function to prevent the divide-by-zero error. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-5247

Affected Products

Xine-Lib