First published: Fri Apr 25 2008(Updated: )
** DISPUTED ** Stack-based buffer overflow in the demux_nsf_send_headers function in src/demuxers/demux_nsf.c in xine-lib allows remote attackers to have an unknown impact via a long copyright field in an NSF header in an NES Sound file, a different issue than CVE-2008-1878. NOTE: a third party claims that the copyright field always has a safe length.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xine |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1964 is a disputed vulnerability that is reported to be capable of causing a stack-based buffer overflow.
To fix CVE-2008-1964, it is recommended to update xine-lib to the latest version that addresses this vulnerability.
CVE-2008-1964 affects the xine-lib software, specifically through its handling of NSF headers in NES Sound files.
Yes, CVE-2008-1964 can potentially be exploited remotely by attackers through specially crafted NES Sound files.
The impact of CVE-2008-1964 is currently unknown but is associated with unauthorized execution or denial of service due to buffer overflow.