See also:
MDVSA-2008:020 
(http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:020)

Quoting:
"Heap-based buffer overflow in the rmff_dump_cont function in
input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote
attackers to execute arbitrary code via the SDP Abstract attribute,
related to the rmff_dump_header function and related to disregarding
the max field. (CVE-2008-0225)

Multiple heap-based buffer overflows in the rmff_dump_cont function
in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers
to execute arbitrary code via the SDP (1) Title, (2) Author, or
(3) Copyright attribute, related to the rmff_dump_header function,
different vectors than CVE-2008-0225. (CVE-2008-0238)"

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2008-0238

-- 
[xine-lib] [CVE-2008-0225] insufficient input sanitising during the handling of 
RTSP streams
https://bugs.launchpad.net/bugs/185034
You received this bug notification because you are a member of Ubuntu
Bugs, which is the bug contact for Ubuntu.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to