Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.50587
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDKSA-2004:105 (xine-lib)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to xine-lib
announced via advisory MDKSA-2004:105.

A number of string overflows were discovered in the xine-lib program,
some of which can be used for remote buffer overflow exploits that
lead to the execution of arbitrary code with the permissions of the
user running a xine-lib-based media application. xine-lib versions
1-rc2 through, and including, 1-rc5 are vulnerable to these problems.

As well, a heap overflow was found in the DVD subpicture decoder of
xine-lib
this vulnerability is also remotely exploitable. All
versions of xine-lib prior to and including 0.5.2 through, and
including, 1-rc5 are vulnerable to this problem.

Patches from the xine-lib team have been backported and applied to
the program to solve these problems.

Affected versions: 10.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2004:105
http://xinehq.de/index.php/security/XSA-2004-4
http://xinehq.de/index.php/security/XSA-2004-5

Risk factor : High

CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.