CVE-2009-0698: Integer Overflow
Published Feb 23, 2009
·Updated
Integer overflow in the 4xm demuxer (demuxers/demux4xm.c) in xine-lib 1.1.16.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a 4X movie file with a large currenttrack value, a similar issue to CVE-2009-0385.
Affected Software
1 affected component
xine Xine-lib=1.1.16.1
Remediation
Event History
Feb 23, 2009
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0698?
CVE-2009-0698 has a critical severity as it allows remote code execution and denial of service.
2
How do I fix CVE-2009-0698?
To fix CVE-2009-0698, update xine-lib to version 1.1.16.2 or later.
3
What is affected by CVE-2009-0698?
CVE-2009-0698 affects xine-lib version 1.1.16.1 specifically.
4
What type of vulnerability is CVE-2009-0698?
CVE-2009-0698 is an integer overflow vulnerability.
5
What could be the consequence of exploiting CVE-2009-0698?
Exploiting CVE-2009-0698 could lead to application crashes and the potential execution of arbitrary code.