CVE-2008-1878: Buffer Overflow
Published Apr 17, 2008
·Updated
Stack-based buffer overflow in the demuxnsfsendchunk function in src/demuxers/demuxnsf.c in xine-lib 1.1.12 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long NSF title.
Affected Software
8 affected components
xine Xine-lib=1.1.10
xine Xine-lib=1.1.10.1
xine Xine-lib=1.1.11
xine Xine-lib=1.1.0
xine Xine-lib=1.1.9
xine Xine-lib<=1.1.12
xine Xine-lib=1.1.11.1
xine Xine-lib=1.1.1
Event History
Apr 17, 2008
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1878?
CVE-2008-1878 has a severity level that allows for remote denial of service and potentially arbitrary code execution.
2
How do I fix CVE-2008-1878?
To fix CVE-2008-1878, upgrade xine-lib to version 1.1.13 or later.
3
Which versions of xine-lib are affected by CVE-2008-1878?
CVE-2008-1878 affects xine-lib versions up to and including 1.1.12.
4
Can CVE-2008-1878 allow attackers to execute code?
Yes, CVE-2008-1878 may allow remote attackers to execute arbitrary code.
5
What type of vulnerability is CVE-2008-1878?
CVE-2008-1878 is a stack-based buffer overflow vulnerability.