CVE-2008-5239: Buffer Overflow
xine-lib 1.1.12, and other 1.1.15 and earlier versions, does not properly handle (a) negative and (b) zero values during unspecified read function calls in inputfile.c, inputnet.c, inputsmb.c, and inputhttp.c, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via vectors such as (1) a file or (2) an HTTP response, which triggers consequences such as out-of-bounds reads and heap-based buffer overflows.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5239?
CVE-2008-5239 has a severity rating that can result in denial of service, making it a significant vulnerability affecting various xine-lib versions.
How do I fix CVE-2008-5239?
To fix CVE-2008-5239, upgrade xine-lib to version 1.1.13 or later, which addresses this vulnerability.
Which versions are affected by CVE-2008-5239?
CVE-2008-5239 affects xine-lib versions 1.1.12 and earlier, including multiple earlier versions like 1.1.10 and 1.1.11.
What kind of attack does CVE-2008-5239 allow?
CVE-2008-5239 allows remote attackers to cause a denial of service through a crash of the affected application.
Is CVE-2008-5239 present in xine-lib version 1.1.15?
Yes, CVE-2008-5239 is present in xine-lib version 1.1.15 and all earlier versions.