CVE-2008-5240: Buffer Overflow
xine-lib 1.1.12, and other 1.1.15 and earlier versions, relies on an untrusted input value to determine the memory allocation and does not check the result for (1) the MATROSKAIDTRCODECPRIVATE track entry element processed by demuxmatroska.c; and (2) PROPTAG, (3) MDPRTAG, and (4) CONTTAG chunks processed by the realparseheaders function in demuxreal.c; which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) or possibly execute arbitrary code via a crafted value.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5240?
CVE-2008-5240 has a medium severity rating due to its potential for causing memory corruption issues.
How do I fix CVE-2008-5240?
To fix CVE-2008-5240, upgrade xine-lib to version 1.1.15 or later.
What versions are affected by CVE-2008-5240?
CVE-2008-5240 affects xine-lib versions 1.1.12 and earlier.
What is the impact of CVE-2008-5240 on applications?
CVE-2008-5240 can lead to memory allocation vulnerabilities that may crash applications or allow attackers to execute arbitrary code.
Is there a workaround for CVE-2008-5240?
A temporary workaround for CVE-2008-5240 is to limit the usage of the affected versions of xine-lib until a patch is applied.