Lucene search

K
freebsdFreeBSD107E2EE5-F941-11DA-B1FA-020039488E34
HistoryMay 31, 2006 - 12:00 a.m.

libxine -- buffer overflow vulnerability

2006-05-3100:00:00
vuxml.freebsd.org
18

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.214

Percentile

96.5%

A Secunia Advisory reports:

Federico L. Bossi Bonin has discovered a weakness in xine-lib,
which can be exploited by malicious people to crash certain
applications on a user’s system.
The weakness is cause due to a heap corruption within the
“xineplug_inp_http.so” plugin when handling an overly large
reply from the HTTP server. This can be exploited to crash
an application that uses the plugin (e.g. gxine).

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchlibxine< 1.1.1_6UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.214

Percentile

96.5%