Lucene search

K
osvGoogleOSV:DSA-1215
HistoryNov 20, 2006 - 12:00 a.m.

xine-lib

2006-11-2000:00:00
Google
osv.dev
20

EPSS

0.072

Percentile

94.0%

Several remote vulnerabilities have been discovered in the Xine multimedia
library, which may lead to the execution of arbitrary code. The Common
Vulnerabilities and Exposures project identifies the following problems:

  • CVE-2006-4799
    The XFocus Security Team discovered that insufficient validation of
    AVI headers may lead to the execution of arbitrary code.
  • CVE-2006-4800
    Michael Niedermayer discovered that a buffer overflow in the 4XM
    codec may lead to the execution of arbitrary code.

For the stable distribution (sarge) these problems have been fixed in
version 1.0.1-1sarge4.

For the upcoming stable distribution (etch) these problems have been
fixed in version 1.1.2-1.

For the unstable distribution (sid) these problems have been fixed in
version 1.1.2-1.

We recommend that you upgrade your xine-lib packages.