FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-1664

This CVE name corresponds to:

Entered Topic
2008-01-29 libxine -- buffer overflow vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-1664
Phase Assigned(20060407)

Description

Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, allows remote attackers to execute arbitrary code via a crafted MPEG stream.

References

Source Reference
MISC http://www.securityfocus.com/data/vulnerabilities/exploits/xinelib_poc.pl
MILW0RM 1641
MISC http://sourceforge.net/project/shownotes.php?group_id=9655&release_id=571608
CONFIRM http://bugs.gentoo.org/show_bug.cgi?id=128838
FEDORA FEDORA-2008-1043
FEDORA FEDORA-2008-1047
GENTOO GLSA-200604-16
BID 17370
SECTRACK 1015868
SECUNIA 19853
SECUNIA 19856
SECUNIA 28666
XF xinelib-mpeg-bo(25670)