CVE-2006-1905: High severity xine xine vulnerability
Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote attackers to execute arbitrary code via format string specifiers in a long filename on an EXTINFO line in a playlist file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1905?
CVE-2006-1905 is classified as a critical vulnerability due to the potential for remote code execution.
How could an attacker exploit CVE-2006-1905?
An attacker can exploit CVE-2006-1905 by crafting a playlist file with a long filename that includes malicious format string specifiers.
What versions of xine are affected by CVE-2006-1905?
CVE-2006-1905 affects multiple versions of xine, including 0.9.18, 1.0.1, and several beta and release candidate versions.
How do I fix CVE-2006-1905?
To fix CVE-2006-1905, update xine to the latest version that addresses these format string vulnerabilities.
What are the potential impacts of CVE-2006-1905?
The potential impacts of CVE-2006-1905 include executing arbitrary code on the victim's system, leading to data loss or system compromise.