Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.61421
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDVSA-2008:178 (xine-lib)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to xine-lib
announced via advisory MDVSA-2008:178.

Alin Rad Pop found an array index vulnerability in the SDP parser
of xine-lib. If a user or automated system were tricked into opening
a malicious RTSP stream, a remote attacker could possibly execute
arbitrary code with the privileges of the user using the program
(CVE-2008-0073).

The ASF demuxer in xine-lib did not properly check the length of
ASF headers. If a user was tricked into opening a crafted ASF file,
a remote attacker could possibly cause a denial of service or execute
arbitrary code with the privileges of the user using the program
(CVE-2008-1110).

The Matroska demuxer in xine-lib did not properly verify frame sizes,
which could possibly lead to the execution of arbitrary code if a
user opened a crafted ASF file (CVE-2008-1161).

Luigi Auriemma found multiple integer overflows in xine-lib. If a
user was tricked into opening a crafted FLV, MOV, RM, MVE, MKV, or
CAK file, a remote attacker could possibly execute arbitrary code
with the privileges of the user using the program (CVE-2008-1482).

Guido Landi found A stack-based buffer overflow in xine-lib
that could allow a remote attacker to cause a denial of service
(crash) and potentially execute arbitrary code via a long NSF title
(CVE-2008-1878).

The updated packages have been patched to correct this issue.

Affected: 2008.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDVSA-2008:178

Risk factor : Critical

CVSS Score:
9.3

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-0073
BugTraq ID: 28312
http://www.securityfocus.com/bid/28312
Debian Security Information: DSA-1536 (Google Search)
http://www.debian.org/security/2008/dsa-1536
Debian Security Information: DSA-1543 (Google Search)
http://www.debian.org/security/2008/dsa-1543
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00456.html
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00143.html
http://security.gentoo.org/glsa/glsa-200804-25.xml
http://security.gentoo.org/glsa/glsa-200808-01.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2008:178
http://www.mandriva.com/security/advisories?name=MDVSA-2008:219
http://secunia.com/secunia_research/2008-10/
http://www.securitytracker.com/id?1019682
http://secunia.com/advisories/28694
http://secunia.com/advisories/29392
http://secunia.com/advisories/29472
http://secunia.com/advisories/29503
http://secunia.com/advisories/29578
http://secunia.com/advisories/29601
http://secunia.com/advisories/29740
http://secunia.com/advisories/29766
http://secunia.com/advisories/29800
http://secunia.com/advisories/30581
http://secunia.com/advisories/31372
http://secunia.com/advisories/31393
http://www.slackware.org/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.392408
SuSE Security Announcement: SUSE-SR:2008:007 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00008.html
SuSE Security Announcement: SUSE-SR:2008:012 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.html
http://www.ubuntu.com/usn/usn-635-1
http://www.vupen.com/english/advisories/2008/0923
http://www.vupen.com/english/advisories/2008/0985
XForce ISS Database: xinelib-sdpplinparse-bo(41339)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41339
Common Vulnerability Exposure (CVE) ID: CVE-2008-1110
https://www.exploit-db.com/exploits/1641
http://security.gentoo.org/glsa/glsa-200802-12.xml
http://secunia.com/advisories/29141
XForce ISS Database: xinelib-demuxasf-bo(41019)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41019
Common Vulnerability Exposure (CVE) ID: CVE-2008-1161
BugTraq ID: 28543
http://www.securityfocus.com/bid/28543
http://secunia.com/advisories/29323
SuSE Security Announcement: SUSE-SR:2008:006 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html
XForce ISS Database: xinelib-demuxer-bo(41172)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41172
Common Vulnerability Exposure (CVE) ID: CVE-2008-1482
BugTraq ID: 28370
http://www.securityfocus.com/bid/28370
Bugtraq: 20080320 Multiple heap overflows in xine-lib 1.1.11 (Google Search)
http://www.securityfocus.com/archive/1/489894/100/0/threaded
Debian Security Information: DSA-1586 (Google Search)
http://www.debian.org/security/2008/dsa-1586
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00157.html
http://aluigi.altervista.org/adv/xinehof-adv.txt
http://aluigi.org/poc/xinehof.zip
http://secunia.com/advisories/29484
http://secunia.com/advisories/29600
http://secunia.com/advisories/29622
http://secunia.com/advisories/29756
http://secunia.com/advisories/30337
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.441137
http://securityreason.com/securityalert/3769
SuSE Security Announcement: SUSE-SR:2008:008 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html
http://www.vupen.com/english/advisories/2008/0981/references
XForce ISS Database: xinelib-multiple-bo(41350)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41350
Common Vulnerability Exposure (CVE) ID: CVE-2008-1878
BugTraq ID: 28816
http://www.securityfocus.com/bid/28816
https://www.exploit-db.com/exploits/5458
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00536.html
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00571.html
http://www.mandriva.com/security/advisories?name=MDVSA-2008:177
http://secunia.com/advisories/29850
http://secunia.com/advisories/30021
http://www.vupen.com/english/advisories/2008/1247/references
XForce ISS Database: xinelib-demuxnsfsendchunk-bo(41865)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41865
CopyrightCopyright (c) 2008 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.