7.5
CVSSv2

CVE-2006-1664

Published: 07/04/2006 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in xine_list_delete_current in libxine 1.14 and previous versions, as distributed in xine-lib 1.1.1 and previous versions, allows remote malicious users to execute arbitrary code via a crafted MPEG stream.

Vulnerable Product Search on Vulmon Subscribe to Product

xine xine-lib 1.0.1

xine xine-lib 1.0.2

xine xine-lib 1.0.3a

xine xine-lib 1.1.0

xine xine-lib 1.1.1

xine xine-lib 0.9.13

xine xine-lib 1.0

Exploits

#!/usr/bin/perl ##################################################################### # Libxine <= 114 : MPEG Stream Buffer overflow vulnerability / PoC # # Federico L Bossi Bonin # fbossi[at]netcommcomar #################################################################### # (gdb) run /tmp/eggmpeg # Starting program: /usr/bin/gxine /tmp/e ...