CVE-2008-5234: Buffer Overflow
Multiple heap-based buffer overflows in xine-lib 1.1.12, and other versions before 1.1.15, allow remote attackers to execute arbitrary code via vectors related to (1) a crafted metadata atom size processed by the parsemoovatom function in demuxqt.c and (2) frame reading in the id3v23interpframe function in id3.c. NOTE: as of 20081122, it is possible that vector 1 has not been fixed in 1.1.15.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5234?
CVE-2008-5234 has a high severity level due to its potential to allow remote code execution.
How do I fix CVE-2008-5234?
To fix CVE-2008-5234, update xine-lib to version 1.1.15 or later.
What software is affected by CVE-2008-5234?
CVE-2008-5234 affects multiple versions of xine-lib prior to version 1.1.15.
Can CVE-2008-5234 be exploited remotely?
Yes, CVE-2008-5234 can be exploited remotely through crafted files processed by xine-lib.
Is CVE-2008-5234 a buffer overflow vulnerability?
Yes, CVE-2008-5234 is a heap-based buffer overflow vulnerability.