FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-0698

This CVE name corresponds to:

Entered Topic
2009-05-17 libxine -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-0698
Phase Assigned(20090223)

Description

Integer overflow in the 4xm demuxer (demuxers/demux_4xm.c) in xine-lib 1.1.16.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a 4X movie file with a large current_track value, a similar issue to CVE-2009-0385.

References

Source Reference
BUGTRAQ 20090128 [TKADV2009-004] FFmpeg Type Conversion Vulnerability
MISC http://www.trapkit.de/advisories/TKADV2009-004.txt
CONFIRM http://bugs.xine-project.org/show_bug.cgi?id=205
CONFIRM http://sourceforge.net/project/shownotes.php?release_id=660071
MANDRIVA MDVSA-2009:298
MANDRIVA MDVSA-2009:299
SUSE SUSE-SR:2009:009
UBUNTU USN-746-1
XF xinelib-4xmdemuxer-code-execution(48954)