7.5
CVSSv2

CVE-2004-1379

Published: 16/09/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in the DVD subpicture decoder in xine xine-lib 1-rc5 and previous versions allows remote malicious users to execute arbitrary code via a (1) DVD or (2) MPEG subpicture header where the second field reuses RLE data from the end of the first field.

Vulnerable Product Search on Vulmon Subscribe to Product

xine xine-lib 0.9.8

xine xine-lib 1_beta7

xine xine-lib 1_beta8

xine xine-lib 1_rc3c

xine xine-lib 1_rc4

xine xine 1_beta2

xine xine 1_beta3

xine xine 1_rc0

xine xine 1_rc0a

xine xine-lib 1_beta3

xine xine-lib 1_beta4

xine xine-lib 1_rc1

xine xine-lib 1_rc2

xine xine 1_beta1

xine xine 1_beta10

xine xine 1_beta6

xine xine 1_beta7

xine xine 1_rc3

xine xine 1_rc3a

xine xine 1_rc3b

xine xine-lib 1_beta12

xine xine-lib 1_beta2

xine xine-lib 1_beta9

xine xine-lib 1_rc0

xine xine-lib 1_rc5

xine xine 1_alpha

xine xine 1_beta4

xine xine 1_beta5

xine xine 1_rc1

xine xine 1_rc2

xine xine-lib 1_beta5

xine xine-lib 1_beta6

xine xine-lib 1_rc3

xine xine-lib 1_rc3a

xine xine-lib 1_rc3b

xine xine 1_beta11

xine xine 1_beta12

xine xine 1_beta8

xine xine 1_beta9

xine xine 1_rc4

xine xine 1_rc5

Vendor Advisories

A heap overflow has been discovered in the DVD subpicture decoder of xine-lib An attacker could cause arbitrary code to be executed on the victims host by supplying a malicious MPEG By tricking users to view a malicious network stream, this is remotely exploitable For the stable distribution (woody) this problem has been fixed in version 098-2 ...