User: Password:
Subscribe / Log in / New account

xine: format string vulnerabilities

Package(s):xine CVE #(s):CVE-2007-0017
Created:January 23, 2007 Updated:August 10, 2007
Description: Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and the (2) cdio_log_handler and (3) vcd_log_handler functions in modules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an invalid URI, as demonstrated by a udp://-- URI in an M3U file.
Mandriva MDKSA-2007:154 xine-ui 2007-08-09
Debian DSA-1252-1 vlc 2007-01-27
Mandriva MDKSA-2007:027 xine-ui 2007-01-26
Gentoo 200701-24 vlc 2007-01-26
SuSE SUSE-SA:2007:013 xine-ui,xine-lib,xine-extra,xine-devel 2007-01-23

(Log in to post comments)

Copyright © 2018, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds