Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2008-5246
HistoryNov 26, 2008 - 1:30 a.m.

CVE-2008-5246

2008-11-2601:30:00
Debian Security Bug Tracker
security-tracker.debian.org
8

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

0.107 Low

EPSS

Percentile

95.1%

Multiple heap-based buffer overflows in xine-lib before 1.1.15 allow remote attackers to execute arbitrary code via vectors that send ID3 data to the (1) id3v22_interp_frame and (2) id3v24_interp_frame functions in src/demuxers/id3.c. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

OSVersionArchitecturePackageVersionFilename
Debian12allvlc< 3.0.21-0+deb12u1vlc_3.0.21-0+deb12u1_all.deb
Debian11allvlc< 3.0.21-0+deb11u1vlc_3.0.21-0+deb11u1_all.deb
Debian999allvlc< 3.0.21-1vlc_3.0.21-1_all.deb
Debian13allvlc< 3.0.21-1vlc_3.0.21-1_all.deb

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

0.107 Low

EPSS

Percentile

95.1%