CVE-2008-1110: Buffer Overflow
Buffer overflow in demuxers/demuxasf.c (aka the ASF demuxer) in the xineplugdmxasf.so plugin in xine-lib before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted ASF header. NOTE: this issue leads to a crash when an attack uses the CVE-2006-1664 exploit code, but it is different from CVE-2006-1664.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1110?
CVE-2008-1110 has a high severity as it allows remote attackers to execute arbitrary code or cause a denial of service.
How do I fix CVE-2008-1110?
To fix CVE-2008-1110, upgrade to xine-lib version 1.1.10 or later.
What software is affected by CVE-2008-1110?
CVE-2008-1110 affects xine-lib versions prior to 1.1.10 and xine-plugin versions prior to 1.1.10.
What type of vulnerability is CVE-2008-1110?
CVE-2008-1110 is a buffer overflow vulnerability in the ASF demuxer.
Can CVE-2008-1110 lead to remote code execution?
Yes, CVE-2008-1110 can allow remote attackers to execute arbitrary code through a crafted ASF header.