Lucene search

K
ubuntuUbuntuUSN-123-1
HistoryMay 06, 2005 - 12:00 a.m.

Xine library vulnerabilities

2005-05-0600:00:00
ubuntu.com
30

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.014

Percentile

86.6%

Releases

  • Ubuntu 5.04
  • Ubuntu 4.10

Details

Two buffer overflows have been discovered in the MMS and Real RTSP
stream handlers of the Xine library. By tricking a user to connect to
a malicious MMS or RTSP video/audio stream source with an application
that uses this library, an attacker could crash the client and
possibly even execute arbitrary code with the privileges of the player
application.

OSVersionArchitecturePackageVersionFilename
Ubuntu5.04noarchlibxine1< *UNKNOWN
Ubuntu4.10noarchlibxine1< *UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.014

Percentile

86.6%