CVE-2008-5243: Input Validation
The realparseheaders function in demuxreal.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, relies on an untrusted input length value to "reindex into an allocated buffer," which allows remote attackers to cause a denial of service (crash) via a crafted value, probably an array index error.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability severity of CVE-2008-5243?
CVE-2008-5243 has a severity rating that typically falls under a denial of service risk, allowing a crash due to untrusted input handling.
How do I fix CVE-2008-5243?
To fix CVE-2008-5243, you should upgrade to xine-lib version 1.1.16 or later.
What software is affected by CVE-2008-5243?
CVE-2008-5243 affects xine-lib versions 1.1.15 and earlier, including several specific versions down to 1.0.
What type of attack does CVE-2008-5243 facilitate?
CVE-2008-5243 allows remote attackers to exploit the vulnerability to trigger a denial of service condition.
Is CVE-2008-5243 a known vulnerability?
Yes, CVE-2008-5243 is a publicly known vulnerability documented in various security databases.