First published: Fri Feb 29 2008(Updated: )
Buffer overflow in demuxers/demux_asf.c (aka the ASF demuxer) in the xineplug_dmx_asf.so plugin in xine-lib before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted ASF header. NOTE: this issue leads to a crash when an attack uses the CVE-2006-1664 exploit code, but it is different from CVE-2006-1664.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
xine | <=1.1.9 | |
Xine | <=1.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1110 has a high severity as it allows remote attackers to execute arbitrary code or cause a denial of service.
To fix CVE-2008-1110, upgrade to xine-lib version 1.1.10 or later.
CVE-2008-1110 affects xine-lib versions prior to 1.1.10 and xine-plugin versions prior to 1.1.10.
CVE-2008-1110 is a buffer overflow vulnerability in the ASF demuxer.
Yes, CVE-2008-1110 can allow remote attackers to execute arbitrary code through a crafted ASF header.