LWN.net Logo

xine-lib: multiple vulnerabilities

Package(s):xine-lib CVE #(s):CVE-2008-5234 CVE-2008-5236 CVE-2008-5237 CVE-2008-5239 CVE-2008-5240 CVE-2008-5243
Created:January 15, 2009 Updated:June 1, 2010
Description: xine-lib has multiple vulnerabilities. The project release notes has more details: - Heap overflow in Quicktime atom parsing. (CVE-2008-5234 vector 1) - Multiple buffer overflows. (CVE-2008-5236) - Multiple integer overflows. (CVE-2008-5237) - Unchecked read function results. (CVE-2008-5239) - Unchecked malloc using untrusted values. (CVE-2008-5240 vectors 3 & 4) - Buffer indexing using an untrusted value. (CVE-2008-5243)
Alerts:
Gentoo 201006-04 2010-06-01
Mandriva MDVSA-2009:319 2009-12-05
Ubuntu USN-746-1 2009-03-26
SuSE SUSE-SR:2009:004 2009-02-17
Fedora FEDORA-2009-1524 2009-02-12
Fedora FEDORA-2009-1525 2009-02-12
Ubuntu USN-710-1 2009-01-26
Fedora FEDORA-2009-0483 2009-01-14
Fedora FEDORA-2009-0542 2009-01-14
Mandriva MDVSA-2009:020 2009-01-21

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds