From e7b51c7f3440f47248dbcaf1b38912c044dfa801 Mon Sep 17 00:00:00 2001 From: remko Date: Sun, 23 Apr 2006 09:35:37 +0000 Subject: Document xine -- multiple remote string vulnerabilities. --- security/vuxml/vuln.xml | 33 +++++++++++++++++++++++++++++++++ 1 file changed, 33 insertions(+) (limited to 'security') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index f5d683680cd4..773e86796737 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -34,6 +34,39 @@ Note: Please add new entries to the beginning of this file. --> + + xine -- multiple remote string vulnerabilities + + + xine + 0.99.4_4 + + + + +

c0ntexb reports:

+
+

There are 2 format string bugs in the latest version of + Xine that could be exploited by a malicious person to + execute code on the system of a remote user running the + media player against a malicious playlist file. By passing + a format specifier in the path of a file that is embedded + in a remote playlist, it is possible to trigger this bug. +

+
+ +
+ + 17579 + CVE-2006-1905 + http://www.open-security.org/advisories/16 + + + 2006-04-18 + 2006-04-23 + +
+ cyrus-sasl -- DIGEST-MD5 Pre-Authentication Denial of Service -- cgit