First published: Wed Nov 26 2008(Updated: )
xine-lib before 1.1.15 performs V4L video frame preallocation before ascertaining the required length, which has unknown impact and attack vectors, possibly related to a buffer overflow in the open_video_capture_device function in src/input/input_v4l.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
xine | =1.1.10 | |
xine | =1-rc3a | |
xine | =1.1.10.1 | |
xine | =1.1.9.1 | |
xine | =1_beta7 | |
xine | =1.1.11 | |
xine | =1-rc3 | |
xine | =1_beta9 | |
xine | =1.1.0 | |
xine | =1.1.7 | |
xine | =1-rc3b | |
xine | =1-rc5 | |
xine | =1.1.2 | |
xine | =1_beta4 | |
xine | =1.1.9 | |
xine | =1.0.3a | |
xine | =1-rc4a | |
xine | =1.1.12 | |
xine | =1.0.1 | |
xine | =1-rc8 | |
xine | =1.1.13 | |
xine | =1.1.11.1 | |
xine | =1-rc2 | |
xine | =1.0.2 | |
xine | =1.1.8 | |
xine | =1_beta2 | |
xine | =1-rc7 | |
xine | =1_beta5 | |
xine | =1_beta11 | |
xine | =1-rc1 | |
xine | =1.1.3 | |
xine | <=1.1.14 | |
xine | =1.1.4 | |
xine | =1.1.5 | |
xine | =0.9.13 | |
xine | =1.0 | |
xine | =1-rc3c | |
xine | =1_beta6 | |
xine | =1-rc4 | |
xine | =1_beta1 | |
xine | =1.1.6 | |
xine | =1_beta12 | |
xine | =1.1.1 | |
xine | =1_beta10 | |
xine | =1_beta8 | |
xine | =1-rc0a | |
xine | =1-rc6a | |
xine | =1_beta3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5245 has an unknown severity level due to the lack of specific details on its impact and exploitability.
To fix CVE-2008-5245, upgrade to xine-lib version 1.1.15 or later.
CVE-2008-5245 is caused by improper preallocation of video frames in xine-lib's V4L implementation before determining the necessary length.
CVE-2008-5245 affects all versions of xine-lib prior to 1.1.15.
The attack vectors for CVE-2008-5245 are currently unknown, but they may relate to potential buffer overflow conditions.