Xine 0.9/1.0 - Playlist Handling Remote Format String

Related Vulnerabilities: CVE-2006-1905  
Publish Date: 18 Apr 2006
Author: c0ntexb

The xine package is reported prone to a remote format-string vulnerability. 

This issue arises when the application handles specially crafted playlist files. An attacker can exploit this vulnerability by crafting a malicious file that contains format specifiers and then sending the file to an unsuspecting user. 

A successful attack may crash the application or lead to arbitrary code execution. 

All versions of xine are considered vulnerable at the moment.
