Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.64000
Kategorie:FreeBSD Local Security Checks
Titel:FreeBSD Ports: libxine
Zusammenfassung:The remote host is missing an update to the system; as announced in the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: libxine

CVE-2009-0698
Integer overflow in the 4xm demuxer (demuxers/demux_4xm.c) in xine-lib
1.1.16.1 allows remote attackers to cause a denial of service (crash)
and possibly execute arbitrary code via a 4X movie file with a large
current_track value, a similar issue to CVE-2009-0385.

CVE-2008-5234
Multiple heap-based buffer overflows in xine-lib 1.1.12, and other
versions before 1.1.15, allow remote attackers to execute arbitrary
code via vectors related to (1) a crafted metadata atom size processed
by the parse_moov_atom function in demux_qt.c and (2) frame reading in
the id3v23_interp_frame function in id3.c. NOTE: as of 20081122, it is
possible that vector 1 has not been fixed in 1.1.15.

CVE-2008-5240
xine-lib 1.1.12, and other 1.1.15 and earlier versions, relies on an
untrusted input value to determine the memory allocation and does not
check the result for (1) the MATROSKA_ID_TR_CODECPRIVATE track entry
element processed by demux_matroska.c, and (2) PROP_TAG, (3) MDPR_TAG,
and (4) CONT_TAG chunks processed by the real_parse_headers function
in demux_real.c, which allows remote attackers to cause a denial of
service (NULL pointer dereference and crash) or possibly execute
arbitrary code via a crafted value.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-0698
Bugtraq: 20090128 [TKADV2009-004] FFmpeg Type Conversion Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/500514/100/0/threaded
http://www.mandriva.com/security/advisories?name=MDVSA-2009:298
http://www.mandriva.com/security/advisories?name=MDVSA-2009:299
http://www.trapkit.de/advisories/TKADV2009-004.txt
SuSE Security Announcement: SUSE-SR:2009:009 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html
http://www.ubuntu.com/usn/USN-746-1
XForce ISS Database: xinelib-4xmdemuxer-code-execution(48954)
https://exchange.xforce.ibmcloud.com/vulnerabilities/48954
Common Vulnerability Exposure (CVE) ID: CVE-2008-5234
BugTraq ID: 30797
http://www.securityfocus.com/bid/30797
Bugtraq: 20080822 [oCERT-2008-008] multiple heap overflows in xine-lib (Google Search)
http://www.securityfocus.com/archive/1/495674/100/0/threaded
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00385.html
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00174.html
https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00555.html
http://www.mandriva.com/security/advisories?name=MDVSA-2009:020
http://www.ocert.org/analysis/2008-008/analysis.txt
http://securitytracker.com/id?1020703
http://secunia.com/advisories/31502
http://secunia.com/advisories/31827
http://secunia.com/advisories/33544
http://securityreason.com/securityalert/4648
SuSE Security Announcement: SUSE-SR:2009:004 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
http://www.vupen.com/english/advisories/2008/2382
XForce ISS Database: xinelib-id3v23interpframe-bo(44647)
https://exchange.xforce.ibmcloud.com/vulnerabilities/44647
XForce ISS Database: xinelib-parsemoovatom-bo(44633)
https://exchange.xforce.ibmcloud.com/vulnerabilities/44633
Common Vulnerability Exposure (CVE) ID: CVE-2008-5240
http://www.osvdb.org/47742
XForce ISS Database: xinelib-demuxmatroska-dos(44653)
https://exchange.xforce.ibmcloud.com/vulnerabilities/44653
CopyrightCopyright (C) 2009 E-Soft Inc.

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.