9.3
CVSSv2

CVE-2008-5245

Published: 26/11/2008 Updated: 08/08/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

xine-lib prior to 1.1.15 performs V4L video frame preallocation before ascertaining the required length, which has unknown impact and attack vectors, possibly related to a buffer overflow in the open_video_capture_device function in src/input/input_v4l.c.

Vulnerable Product Search on Vulmon Subscribe to Product

xine xine-lib 1.1.9

xine xine-lib 1.1.9.1

xine xine-lib 1.1.2

xine xine-lib 1.1.1

xine xine-lib 1

xine xine-lib 1_beta7

xine xine-lib 1_beta6

xine xine-lib 1.1.11.1

xine xine-lib 1.1.11

xine xine-lib 1.1.6

xine xine-lib 1.1.5

xine xine-lib 1.0.2

xine xine-lib 1.0.1

xine xine-lib 1_beta11

xine xine-lib 1_beta10

xine xine-lib 1_beta3

xine xine-lib 1_beta2

xine xine-lib 1.1.13

xine xine-lib 1.1.12

xine xine-lib 1.1.8

xine xine-lib 1.1.7

xine xine-lib 1.0.3a

xine xine-lib 1.1.0

xine xine-lib 1_beta12

xine xine-lib 1_beta5

xine xine-lib 1_beta4

xine xine-lib 1.1.10.1

xine xine-lib 1.1.10

xine xine-lib 1.1.4

xine xine-lib 1.1.3

xine xine-lib 1.0

xine xine-lib 1_beta9

xine xine-lib 1_beta8

xine xine-lib 1_beta1

xine xine-lib 0.9.13

xine xine-lib

Vendor Advisories

Debian Bug report logs - #498243 xine-lib: multiple heap overflows Package: xine-lib; Maintainer for xine-lib is (unknown); Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Mon, 8 Sep 2008 12:27:02 UTC Severity: grave Tags: help, security, upstream Done: Nico Golde <nion@debianorg> Bug is archive ...