5
CVSSv2

CVE-2006-2230

Published: 05/05/2006 Updated: 18/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.4 might allow malicious users to cause a denial of service via format string specifiers in an MP3 filename specified on the command line. NOTE: this is a different vulnerability than CVE-2006-1905. In addition, if the only attack vectors involve a user-assisted, local command line argument of a non-setuid program, this issue might not be a vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

xine xine 0.99.4

Vendor Advisories

Debian Bug report logs - #363370 xine-ui: printf missing-format-string bugs Package: xine-ui; Maintainer for xine-ui is Darren Salt <devspam@moreofthesameuk>; Source for xine-ui is src:xine-ui (PTS, buildd, popcon) Reported by: Darren Salt <linux@youmustbejokingdemoncouk> Date: Tue, 18 Apr 2006 18:48:04 UTC Sev ...

Exploits

source: wwwsecurityfocuscom/bid/17769/info The xine package is susceptible to a remote format-string vulnerability This issue arises when the application handles specially crafted filenames An attacker can exploit this vulnerability by crafting a malicious filename that contains format specifiers and then coercing unsuspecting users t ...