CVE-2008-5247: Medium severity xine vulnerability
The realparseaudiospecificdata function in demuxreal.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, uses an untrusted height (aka codecdatalength) value as a divisor, which allow remote attackers to cause a denial of service (divide-by-zero error and crash) via a zero value.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5247?
CVE-2008-5247 has a severity level that can lead to a denial of service due to a divide-by-zero error.
How do I fix CVE-2008-5247?
To fix CVE-2008-5247, upgrade to xine-lib version 1.1.15 or later, where the issue has been addressed.
Which versions are affected by CVE-2008-5247?
CVE-2008-5247 affects xine-lib versions up to and including 1.1.14.
What is the exploitability of CVE-2008-5247?
CVE-2008-5247 can be exploited remotely to crash the application, leading to a denial of service.
What component is vulnerable in CVE-2008-5247?
The vulnerability in CVE-2008-5247 is found in the real_parse_audio_specific_data function in demux_real.c.