CVE-2008-0073: Medium severity red hat fedora vulnerability
Published Mar 24, 2008
·Updated
Array index error in the sdpplinparse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parameter.
Affected Software
2 affected components
redhat Fedora=8
xine Xine-lib=1.1.10.1
Remediation
Patch Available
Event History
Mar 24, 2008
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
10:44 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-0073?
CVE-2008-0073 has been classified as a critical vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2008-0073?
To fix CVE-2008-0073, you should upgrade xine-lib to version 1.1.10.2 or later, which addresses this vulnerability.
3
What software is affected by CVE-2008-0073?
CVE-2008-0073 specifically affects xine-lib version 1.1.10.1.
4
Can CVE-2008-0073 be exploited remotely?
Yes, CVE-2008-0073 can be exploited by remote RTSP servers to execute arbitrary code.
5
What is the nature of the vulnerability in CVE-2008-0073?
CVE-2008-0073 is an array index error in the sdpplin_parse function that can lead to code execution.