CVE-2006-2230: Medium severity xine xine vulnerability
Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.4 might allow attackers to cause a denial of service via format string specifiers in an MP3 filename specified on the command line. NOTE: this is a different vulnerability than CVE-2006-1905. In addition, if the only attack vectors involve a user-assisted, local command line argument of a non-setuid program, this issue might not be a vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2230?
CVE-2006-2230 is classified as a medium-severity vulnerability due to its potential for causing denial of service.
How do I fix CVE-2006-2230?
To fix CVE-2006-2230, upgrade to a later version of xine that addresses this vulnerability.
What does CVE-2006-2230 affect?
CVE-2006-2230 specifically affects xine version 0.99.4.
What type of vulnerability is CVE-2006-2230?
CVE-2006-2230 is a format string vulnerability that may lead to denial of service.
Can CVE-2006-2230 be exploited remotely?
Yes, CVE-2006-2230 can be exploited remotely through malicious MP3 filenames provided on the command line.