Lucene search

K
cve[email protected]CVE-2008-5247
HistoryNov 26, 2008 - 1:30 a.m.

CVE-2008-5247

2008-11-2601:30:00
CWE-189
web.nvd.nist.gov
22
cve-2008-5247
xine-lib
demux_real.c
remote attackers
denial of service
divide-by-zero error

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

7.2 High

AI Score

Confidence

High

0.022 Low

EPSS

Percentile

89.6%

The real_parse_audio_specific_data function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, uses an untrusted height (aka codec_data_length) value as a divisor, which allow remote attackers to cause a denial of service (divide-by-zero error and crash) via a zero value.

Affected configurations

NVD
Node
xinexine-libRange1.1.15
OR
xinexine-libMatch0.9.13
OR
xinexine-libMatch1rc0a
OR
xinexine-libMatch1rc1
OR
xinexine-libMatch1rc2
OR
xinexine-libMatch1rc3
OR
xinexine-libMatch1rc3a
OR
xinexine-libMatch1rc3b
OR
xinexine-libMatch1rc3c
OR
xinexine-libMatch1rc4
OR
xinexine-libMatch1rc4a
OR
xinexine-libMatch1rc5
OR
xinexine-libMatch1rc6a
OR
xinexine-libMatch1rc7
OR
xinexine-libMatch1rc8
OR
xinexine-libMatch1.0
OR
xinexine-libMatch1.0.1
OR
xinexine-libMatch1.0.2
OR
xinexine-libMatch1.0.3a
OR
xinexine-libMatch1.1.0
OR
xinexine-libMatch1.1.1
OR
xinexine-libMatch1.1.2
OR
xinexine-libMatch1.1.3
OR
xinexine-libMatch1.1.4
OR
xinexine-libMatch1.1.5
OR
xinexine-libMatch1.1.6
OR
xinexine-libMatch1.1.7
OR
xinexine-libMatch1.1.8
OR
xinexine-libMatch1.1.9
OR
xinexine-libMatch1.1.9.1
OR
xinexine-libMatch1.1.10
OR
xinexine-libMatch1.1.10.1
OR
xinexine-libMatch1.1.11
OR
xinexine-libMatch1.1.11.1
OR
xinexine-libMatch1.1.12
OR
xinexine-libMatch1.1.13
OR
xinexine-libMatch1.1.14
OR
xinexine-libMatch1_beta1
OR
xinexine-libMatch1_beta2
OR
xinexine-libMatch1_beta3
OR
xinexine-libMatch1_beta4
OR
xinexine-libMatch1_beta5
OR
xinexine-libMatch1_beta6
OR
xinexine-libMatch1_beta7
OR
xinexine-libMatch1_beta8
OR
xinexine-libMatch1_beta9
OR
xinexine-libMatch1_beta10
OR
xinexine-libMatch1_beta11
OR
xinexine-libMatch1_beta12

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

7.2 High

AI Score

Confidence

High

0.022 Low

EPSS

Percentile

89.6%