CVE-2008-5237: Integer Overflow
Multiple integer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) crafted width and height values that are not validated by the mymngprocessheader function in demuxmng.c before use in an allocation calculation or (2) crafted currentatomsize and stringsize values processed by the parsereferenceatom function in demuxqt.c for an RDRFATOM string.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5237?
CVE-2008-5237 is classified as a high severity vulnerability due to the potential for remote code execution and denial of service.
How do I fix CVE-2008-5237?
To address CVE-2008-5237, update xine-lib to version 1.1.16 or later, which resolves the integer overflow issues.
What versions of xine-lib are affected by CVE-2008-5237?
CVE-2008-5237 affects xine-lib versions 1.1.12 and earlier, including all beta and release candidate versions.
What type of vulnerability is CVE-2008-5237?
CVE-2008-5237 is an integer overflow vulnerability that can be exploited by sending crafted width and height values.
Can CVE-2008-5237 lead to remote execution attacks?
Yes, CVE-2008-5237 can potentially allow remote attackers to execute arbitrary code by exploiting the overflow vulnerabilities.