4.3
CVSSv2

CVE-2008-3231

Published: 18/07/2008 Updated: 08/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

xine-lib prior to 1.1.15 allows remote malicious users to cause a denial of service (crash) via a crafted OGG file, as demonstrated by playing lol-ffplay.ogg with xine.

Vulnerable Product Search on Vulmon Subscribe to Product

xine xine-lib 1.1.1

xine xine-lib 1.1.0

xine xine-lib 1.1.13

xine xine-lib 1.1.2

xine xine-lib 1.1.4

xine xine-lib 1.1.5

xine xine-lib 1

xine xine-lib 1.0.2

xine xine-lib 1.0.1

xine xine-lib 1.1.10.1

xine xine-lib 1.1.11.1

xine xine-lib 1.1.8

xine xine-lib 1.1.9

xine xine-lib 0.99

xine xine-lib 1.0.3a

xine xine-lib 1.1.3

xine xine-lib 1.1.12

xine xine-lib 1.1.6

xine xine-lib 1.1.7

xine xine-lib 0.9.8

xine xine-lib 0.9.13

xine xine-lib 1.0

xine xine-lib 1.1.11

xine xine-lib 1.1.10

xine xine-lib

xine xine-lib 1.1.9.1

Vendor Advisories

It was discovered that xine-lib did not correctly handle certain malformed Ogg and Windows Media files If a user or automated system were tricked into opening a specially crafted Ogg or Windows Media file, an attacker could cause xine-lib to crash, creating a denial of service This issue only applied to Ubuntu 606 LTS, 710, and 804 LTS (CVE-2 ...