Search:     Advanced search
server monitoring

SSA-2005-283-01 xine-lib

Article ID: 19952
Last updated: 27 Jan, 2009
Views: 369
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

SSA-2005-283-01 xine-lib

This script is Copyright (C) 2005 Tenable Network Security, Inc.

FamilySlackware Local Security Checks
Plugin ID19952
Bugtraq ID
CVE ID

Description:

New xine-lib packages are available for Slackware 9.1, 10.0, 10.1, 10.2,
and -current to fix a security issue. A format string bug may allow the
execution of arbitrary code as the user running a xine-lib linked
application. The attacker must provide (by uploading or running a server)
specially crafted CDDB information and then get the user to play the
referenced audio CD.

The official Xine advisory may be found here:

http://xinehq.de/index.php/security/XSA-2005-1


This article was:   Helpful | Not Helpful
Prev   Next
SSA-2005-195-10 tcpdump DoS      SSA-2005-242-02 PHP