|
|
Subscribe / Log in / New account

xine-lib: arbitrary code execution

Package(s):xine-lib CVE #(s):CAN-2005-2967
Created:October 10, 2005 Updated:October 12, 2005
Description: Ulf Harnhammar discovered a format string vulnerability in the CDDB module's cache file handling in the Xine library, which is used by packages such as xine-ui, totem-xine, and gxine. By tricking an user into playing a particular audio CD which has a specially-crafted CDDB entry, a remote attacker could exploit this vulnerability to execute arbitrary code with the privileges of the user running the application. Since CDDB servers usually allow anybody to add and modify information, this exploit does not even require a particular CDDB server to be selected.
Alerts:
Mandriva MDKSA-2005:180 xine-lib 2005-10-11
Debian DSA-863-1 xine-lib 2005-10-12
Slackware SSA:2005-283-01 xine 2005-10-11
Ubuntu USN-196-1 xine-lib 2005-10-10
Gentoo 200510-08 xine-lib 2005-10-08

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds