Lucene search

K
ubuntuUbuntuUSN-295-1
HistoryJun 09, 2006 - 12:00 a.m.

xine-lib vulnerability

2006-06-0900:00:00
ubuntu.com
36

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

7.3

Confidence

Low

EPSS

0.214

Percentile

96.5%

Releases

  • Ubuntu 6.06
  • Ubuntu 5.10
  • Ubuntu 5.04

Details

Federico L. Bossi Bonin discovered a buffer overflow in the HTTP input
module. By tricking an user into opening a malicious remote media
location, a remote attacker could exploit this to crash Xine library
frontends (like totem-xine, gxine, or xine-ui) and possibly even
execute arbitrary code with the user’s privileges.

OSVersionArchitecturePackageVersionFilename
Ubuntu6.06noarchlibxine-main1< 1.1.1+ubuntu2-7.1UNKNOWN
Ubuntu5.10noarchlibxine1c2< 1.0.1-1ubuntu10.3UNKNOWN
Ubuntu5.04noarchlibxine1< 1.0-1ubuntu3.7UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

7.3

Confidence

Low

EPSS

0.214

Percentile

96.5%