FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-2802

This CVE name corresponds to:

Entered Topic
2006-06-11 libxine -- buffer overflow vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-2802
Phase Assigned(20060602)

Description

Buffer overflow in the HTTP Plugin (xineplug_inp_http.so) for xine-lib 1.1.1 allows remote attackers to cause a denial of service (application crash) via a long reply from an HTTP server, as demonstrated using gxine 0.5.6.

References

Source Reference
MILW0RM 1852
DEBIAN DSA-1105
GENTOO GLSA-200609-08
MANDRAKE MDKSA-2006:108
MANDRIVA MDKSA-2006:108
SUSE SUSE-SR:2006:014
UBUNTU USN-295-1
BID 18187
OSVDB 25936
SECUNIA 20369
SECUNIA 20549
SECUNIA 20766
SECUNIA 20828
SECUNIA 20942
SECUNIA 21919
XF xinelib-xinepluginphttp-bo(26972)