Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.57610
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDKSA-2006:176 (xine-lib)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to xine-lib
announced via advisory MDKSA-2006:176.

Xine-lib uses an embedded copy of ffmpeg and as such has been updated
to address the following issue: Multiple buffer overflows in
libavcodec in ffmpeg before 0.4.9_p20060530 allow remote attackers to
cause a denial of service or possibly execute arbitrary code via
multiple unspecified vectors in (1) dtsdec.c, (2) vorbis.c, (3) rm.c,
(4)sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8) alac.c, (9)
cook.c, (10)shorten.c, (11) smacker.c, (12) snow.c, and (13) tta.c.
NOTE: it is likely that this is a different vulnerability than
CVE-2005-4048 and CVE-2006-2802.

Updated packages have been patched to correct this issue.

Affected: 2006.0, 2007.0, Corporate 3.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2006:176

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-4048
BugTraq ID: 15743
http://www.securityfocus.com/bid/15743
Debian Security Information: DSA-1004 (Google Search)
http://www.debian.org/security/2006/dsa-1004
Debian Security Information: DSA-1005 (Google Search)
http://www.debian.org/security/2006/dsa-1005
Debian Security Information: DSA-992 (Google Search)
http://www.us.debian.org/security/2006/dsa-992
http://www.gentoo.org/security/en/glsa/glsa-200601-06.xml
http://www.gentoo.org/security/en/glsa/glsa-200602-01.xml
http://www.gentoo.org/security/en/glsa/glsa-200603-03.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2005:228
http://www.mandriva.com/security/advisories?name=MDKSA-2005:229
http://www.mandriva.com/security/advisories?name=MDKSA-2005:230
http://www.mandriva.com/security/advisories?name=MDKSA-2005:231
http://www.mandriva.com/security/advisories?name=MDKSA-2005:232
http://article.gmane.org/gmane.comp.video.ffmpeg.devel/26558
http://secunia.com/advisories/17892
http://secunia.com/advisories/18066
http://secunia.com/advisories/18087
http://secunia.com/advisories/18107
http://secunia.com/advisories/18400
http://secunia.com/advisories/18739
http://secunia.com/advisories/18746
http://secunia.com/advisories/19114
http://secunia.com/advisories/19192
http://secunia.com/advisories/19272
http://secunia.com/advisories/19279
https://usn.ubuntu.com/230-1/
https://usn.ubuntu.com/230-2/
http://www.vupen.com/english/advisories/2005/2770
Common Vulnerability Exposure (CVE) ID: CVE-2006-2802
BugTraq ID: 18187
http://www.securityfocus.com/bid/18187
Debian Security Information: DSA-1105 (Google Search)
http://www.debian.org/security/2006/dsa-1105
https://www.exploit-db.com/exploits/1852
http://security.gentoo.org/glsa/glsa-200609-08.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:108
http://www.osvdb.org/25936
http://secunia.com/advisories/20369
http://secunia.com/advisories/20549
http://secunia.com/advisories/20766
http://secunia.com/advisories/20828
http://secunia.com/advisories/20942
http://secunia.com/advisories/21919
SuSE Security Announcement: SUSE-SR:2006:014 (Google Search)
http://lists.suse.com/archive/suse-security-announce/2006-Jun/0008.html
https://usn.ubuntu.com/295-1/
XForce ISS Database: xinelib-xinepluginphttp-bo(26972)
https://exchange.xforce.ibmcloud.com/vulnerabilities/26972
Common Vulnerability Exposure (CVE) ID: CVE-2006-4800
BugTraq ID: 20009
http://www.securityfocus.com/bid/20009
Debian Security Information: DSA-1215 (Google Search)
http://www.us.debian.org/security/2006/dsa-1215
http://security.gentoo.org/glsa/glsa-200609-09.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:173
http://www.mandriva.com/security/advisories?name=MDKSA-2006:174
http://www.mandriva.com/security/advisories?name=MDKSA-2006:175
http://www.mandriva.com/security/advisories?name=MDKSA-2006:176
http://bugs.gentoo.org/show_bug.cgi?id=133520
http://secunia.com/advisories/21921
http://secunia.com/advisories/22180
http://secunia.com/advisories/22181
http://secunia.com/advisories/22182
http://secunia.com/advisories/22198
http://secunia.com/advisories/22200
http://secunia.com/advisories/22201
http://secunia.com/advisories/22202
http://secunia.com/advisories/22203
http://secunia.com/advisories/22230
http://secunia.com/advisories/23010
http://secunia.com/advisories/23213
SuSE Security Announcement: SUSE-SA:2006:073 (Google Search)
http://www.novell.com/linux/security/advisories/2006_73_mono.html
http://www.ubuntu.com/usn/usn-358-1
CopyrightCopyright (c) 2006 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.