CVE-2008-5242: Buffer Overflow
demuxqt.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, does not validate the count field before calling calloc for STSDATOM atom allocation, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted media file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5242?
CVE-2008-5242 is considered a critical vulnerability that can lead to denial of service or potentially arbitrary code execution.
How do I fix CVE-2008-5242?
To fix CVE-2008-5242, update xine-lib to version 1.1.15 or later.
What types of attacks can exploit CVE-2008-5242?
CVE-2008-5242 can be exploited by attackers sending crafted media files to cause application crashes or execute malicious code.
Which versions of xine-lib are affected by CVE-2008-5242?
CVE-2008-5242 affects xine-lib versions 1.1.15 and earlier, including specific versions up to 1.1.12.
What is the impact of exploiting CVE-2008-5242?
Exploiting CVE-2008-5242 can result in application crashes or allow attackers to run arbitrary code on the affected system.