FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-2967

This CVE name corresponds to:

Entered Topic
2005-10-09 libxine -- format string vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-2967
Phase Assigned(20050919)

Description

Format string vulnerability in input_cdda.c in xine-lib 1-beta through 1-beta 3, 1-rc, 1.0 through 1.0.2, and 1.1.1 allows remote servers to execute arbitrary code via format string specifiers in metadata in CDDB server responses when the victim plays a CD.

References

Source Reference
FULLDISC 20051008 xine/gxine CD Player Remote Format String Bug
CONFIRM http://xinehq.de/index.php/security/XSA-2005-1
DEBIAN DSA-863
GENTOO GLSA-200510-08
MANDRIVA MDKSA-2005:180
SLACKWARE SSA:2005-283-01
SUSE SUSE-SR:2005:024
UBUNTU USN-196-1
BID 15044
OSVDB 19892
SECUNIA 17099
SECUNIA 17132
SECUNIA 17162
SECUNIA 17179
SECUNIA 17097
SECUNIA 17111
SECUNIA 17282
XF xinelib-inputcdda-format-string(22545)