First published: Thu Apr 20 2006(Updated: )
Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote attackers to execute arbitrary code via format string specifiers in a long filename on an EXTINFO line in a playlist file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
xine xine | =1_rc6a | |
xine xine | =1.0.1 | |
xine xine | =1_beta9 | |
xine xine | =0.9.18 | |
xine xine | =1_beta3 | |
xine xine | =1_rc0a | |
xine xine | =1_rc7 | |
xine xine | =1_rc4 | |
xine xine | =1_alpha | |
xine xine | =1_beta4 | |
xine xine | =1_rc3b | |
xine xine | =1_beta2 | |
xine xine | =0.9.8 | |
xine xine | =1_rc3a | |
xine xine | =1_rc2 | |
xine xine | =1_rc8 | |
xine xine | =1.0 | |
xine xine | =1_beta10 | |
xine xine | =1_beta12 | |
xine xine | =1_beta11 | |
xine xine | =1_beta7 | |
xine xine | =1_beta8 | |
xine xine | =0.9.13 | |
xine xine | =1_rc1 | |
xine xine | =1_rc5 | |
xine xine | =1_beta6 | |
xine xine | =1_beta1 | |
xine xine | =1_rc6 | |
xine xine | =1_rc3 | |
xine xine | =1_rc0 | |
xine xine | =1_beta5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1905 is classified as a critical vulnerability due to the potential for remote code execution.
An attacker can exploit CVE-2006-1905 by crafting a playlist file with a long filename that includes malicious format string specifiers.
CVE-2006-1905 affects multiple versions of xine, including 0.9.18, 1.0.1, and several beta and release candidate versions.
To fix CVE-2006-1905, update xine to the latest version that addresses these format string vulnerabilities.
The potential impacts of CVE-2006-1905 include executing arbitrary code on the victim's system, leading to data loss or system compromise.