Lucene search

K
cveMitreCVE-2008-5243
HistoryNov 26, 2008 - 1:30 a.m.

CVE-2008-5243

2008-11-2601:30:00
CWE-20
mitre
web.nvd.nist.gov
37
cve-2008-5243
xine-lib
demux_real.c
denial of service
buffer overflow
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

7.1

Confidence

High

EPSS

0.257

Percentile

96.7%

The real_parse_headers function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, relies on an untrusted input length value to “reindex into an allocated buffer,” which allows remote attackers to cause a denial of service (crash) via a crafted value, probably an array index error.

Affected configurations

Nvd
Node
xinexine-libRange1.1.15
OR
xinexine-libMatch0.9.13
OR
xinexine-libMatch1rc0a
OR
xinexine-libMatch1rc1
OR
xinexine-libMatch1rc2
OR
xinexine-libMatch1rc3
OR
xinexine-libMatch1rc3a
OR
xinexine-libMatch1rc3b
OR
xinexine-libMatch1rc3c
OR
xinexine-libMatch1rc4
OR
xinexine-libMatch1rc4a
OR
xinexine-libMatch1rc5
OR
xinexine-libMatch1rc6a
OR
xinexine-libMatch1rc7
OR
xinexine-libMatch1rc8
OR
xinexine-libMatch1.0
OR
xinexine-libMatch1.0.1
OR
xinexine-libMatch1.0.2
OR
xinexine-libMatch1.0.3a
OR
xinexine-libMatch1.1.0
OR
xinexine-libMatch1.1.1
OR
xinexine-libMatch1.1.2
OR
xinexine-libMatch1.1.3
OR
xinexine-libMatch1.1.4
OR
xinexine-libMatch1.1.5
OR
xinexine-libMatch1.1.6
OR
xinexine-libMatch1.1.7
OR
xinexine-libMatch1.1.8
OR
xinexine-libMatch1.1.9
OR
xinexine-libMatch1.1.9.1
OR
xinexine-libMatch1.1.10
OR
xinexine-libMatch1.1.10.1
OR
xinexine-libMatch1.1.11
OR
xinexine-libMatch1.1.11.1
OR
xinexine-libMatch1.1.12
OR
xinexine-libMatch1.1.13
OR
xinexine-libMatch1.1.14
OR
xinexine-libMatch1_beta1
OR
xinexine-libMatch1_beta2
OR
xinexine-libMatch1_beta3
OR
xinexine-libMatch1_beta4
OR
xinexine-libMatch1_beta5
OR
xinexine-libMatch1_beta6
OR
xinexine-libMatch1_beta7
OR
xinexine-libMatch1_beta8
OR
xinexine-libMatch1_beta9
OR
xinexine-libMatch1_beta10
OR
xinexine-libMatch1_beta11
OR
xinexine-libMatch1_beta12
VendorProductVersionCPE
xinexine-lib*cpe:2.3:a:xine:xine-lib:*:*:*:*:*:*:*:*
xinexine-lib0.9.13cpe:2.3:a:xine:xine-lib:0.9.13:*:*:*:*:*:*:*
xinexine-lib1cpe:2.3:a:xine:xine-lib:1:rc0a:*:*:*:*:*:*
xinexine-lib1cpe:2.3:a:xine:xine-lib:1:rc1:*:*:*:*:*:*
xinexine-lib1cpe:2.3:a:xine:xine-lib:1:rc2:*:*:*:*:*:*
xinexine-lib1cpe:2.3:a:xine:xine-lib:1:rc3:*:*:*:*:*:*
xinexine-lib1cpe:2.3:a:xine:xine-lib:1:rc3a:*:*:*:*:*:*
xinexine-lib1cpe:2.3:a:xine:xine-lib:1:rc3b:*:*:*:*:*:*
xinexine-lib1cpe:2.3:a:xine:xine-lib:1:rc3c:*:*:*:*:*:*
xinexine-lib1cpe:2.3:a:xine:xine-lib:1:rc4:*:*:*:*:*:*
Rows per page:
1-10 of 491

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

7.1

Confidence

High

EPSS

0.257

Percentile

96.7%