Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

xine-lib NES Sound Format Demuxer 'copyright' Buffer Overflow Vulnerability

The 'xine-lib' library is prone to a buffer-overflow vulnerability because the software fails to perform adequate boundary checks on user-supplied data.

An attacker may exploit this issue to execute arbitrary code with the privileges of the user running an application that relies on the affected library. Failed exploit attempts will likely result in denial-of-service conditions.

This issue affects xine-lib 1.1.12 and prior versions.

UPDATE (April 24, 2008): Guido Landi states that this is not a vulnerability because the buffer cannot be overrun. Symantec has not confirmed this.







 

Privacy Statement
Copyright 2009, SecurityFocus