7.5
CVSSv2

CVE-2006-1905

Published: 20/04/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote malicious users to execute arbitrary code via format string specifiers in a long filename on an EXTINFO line in a playlist file.

Vulnerable Product Search on Vulmon Subscribe to Product

xine xine 0.9.13

xine xine 0.9.18

xine xine 1_beta11

xine xine 1_beta12

xine xine 1_beta9

xine xine 1_rc0

xine xine 1_rc4

xine xine 1_rc5

xine xine 1.0.1

xine xine 1_alpha

xine xine 1_beta4

xine xine 1_beta5

xine xine 1_beta6

xine xine 1_rc2

xine xine 1_rc3

xine xine 1_rc7

xine xine 1_rc8

xine xine 1_beta1

xine xine 1_beta10

xine xine 1_beta7

xine xine 1_beta8

xine xine 1_rc3a

xine xine 1_rc3b

xine xine 0.9.8

xine xine 1.0

xine xine 1_beta2

xine xine 1_beta3

xine xine 1_rc0a

xine xine 1_rc1

xine xine 1_rc6

xine xine 1_rc6a

Vendor Advisories

Debian Bug report logs - #363370 xine-ui: printf missing-format-string bugs Package: xine-ui; Maintainer for xine-ui is Darren Salt <devspam@moreofthesameuk>; Source for xine-ui is src:xine-ui (PTS, buildd, popcon) Reported by: Darren Salt <linux@youmustbejokingdemoncouk> Date: Tue, 18 Apr 2006 18:48:04 UTC Sev ...

Exploits

source: wwwsecurityfocuscom/bid/17579/info The xine package is reported prone to a remote format-string vulnerability This issue arises when the application handles specially crafted playlist files An attacker can exploit this vulnerability by crafting a malicious file that contains format specifiers and then sending the file to an un ...