CVE-2008-5235: Buffer Overflow
Heap-based buffer overflow in the demuxrealsendchunk function in src/demuxers/demuxreal.c in xine-lib before 1.1.15 allows remote attackers to execute arbitrary code via a crafted Real Media file. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5235?
CVE-2008-5235 is classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2008-5235?
To fix CVE-2008-5235, upgrade xine-lib to version 1.1.15 or newer.
What is CVE-2008-5235?
CVE-2008-5235 is a heap-based buffer overflow vulnerability in xine-lib that allows remote attackers to execute arbitrary code via crafted Real Media files.
Which versions of xine are affected by CVE-2008-5235?
CVE-2008-5235 affects multiple versions of xine, including all versions prior to 1.1.15.
What should I do if I cannot upgrade xine to mitigate CVE-2008-5235?
If upgrading is not possible, consider implementing a network-based solution to block potentially harmful Real Media files.