See also: MDVSA-2008:020 (http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:020)
Quoting: "Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary code via the SDP Abstract attribute, related to the rmff_dump_header function and related to disregarding the max field. (CVE-2008-0225) Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to execute arbitrary code via the SDP (1) Title, (2) Author, or (3) Copyright attribute, related to the rmff_dump_header function, different vectors than CVE-2008-0225. (CVE-2008-0238)" ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2008-0238 -- [xine-lib] [CVE-2008-0225] insufficient input sanitising during the handling of RTSP streams https://bugs.launchpad.net/bugs/185034 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubuntu. -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
