Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2008-0073
HistoryMar 24, 2008 - 10:44 p.m.

CVE-2008-0073

2008-03-2422:44:00
Debian Security Bug Tracker
security-tracker.debian.org
12

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.004 Low

EPSS

Percentile

74.5%

Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parameter.

OSVersionArchitecturePackageVersionFilename
Debian12allvlc<Β 0.8.6.e-2vlc_0.8.6.e-2_all.deb
Debian11allvlc<Β 0.8.6.e-2vlc_0.8.6.e-2_all.deb
Debian999allvlc<Β 0.8.6.e-2vlc_0.8.6.e-2_all.deb
Debian13allvlc<Β 0.8.6.e-2vlc_0.8.6.e-2_all.deb

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.004 Low

EPSS

Percentile

74.5%