CVE-2008-1686: Critical severity xine vulnerability
Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative offset, which is used to dereference a function pointer.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1686?
CVE-2008-1686 has a high severity rating as it allows remote attackers to execute arbitrary code.
How do I fix CVE-2008-1686?
To fix CVE-2008-1686, update your Speex library to version 1.1.12 or later.
Which software is affected by CVE-2008-1686?
CVE-2008-1686 affects the Speex library versions 1.1.12 and earlier, and various versions of libfishsound and xine-lib.
Can CVE-2008-1686 be exploited remotely?
Yes, CVE-2008-1686 can be exploited remotely due to the vulnerability in header structure processing.
What types of attacks can be carried out due to CVE-2008-1686?
Exploiting CVE-2008-1686 can lead to remote code execution attacks, allowing attackers to gain unauthorized access.