PT-2008-6389 · Xine · Xine-Lib
Will Drewry
·
Published
2008-11-26
·
Updated
2018-10-11
·
CVE-2008-5247
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
xine-lib versions 1.1.12 through 1.1.15
Description
The issue concerns the
real parse audio specific data function in demux real.c, which uses an untrusted height value, also referred to as codec data length, as a divisor. This allows remote attackers to cause a denial of service by triggering a divide-by-zero error and crash via a zero value.Recommendations
For xine-lib versions 1.1.12 through 1.1.15, consider applying a patch that checks for and handles the zero value in the
real parse audio specific data function to prevent the divide-by-zero error.
At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xine-Lib