CVE-2008-5233

NONE EPSS 87.2%
Published Nov 26, 200817y ago · Modified Jun 16, 20262w ago
Find Similar
Published Nov 26, 2008 17y ago
Last Modified Jun 16, 2026 2w ago

Description

xine-lib 1.1.12, and other versions before 1.1.15, does not check for failure of malloc in circumstances including (1) the mymng_process_header function in demux_mng.c, (2) the open_mod_file function in demux_mod.c, and (3) frame_buffer allocation in the real_parse_audio_specific_data function in demux_real.c, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted media file.

Threat Intelligence

EPSS Exploit Probability
87.2% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer Memory Safety

Affected Products 48

VendorProductVersionRange
xinexine-lib* ≤1.1.14
xinexine-lib0.9.13any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1.0any
xinexine-lib1.0.1any
xinexine-lib1.0.2any
xinexine-lib1.0.3aany
xinexine-lib1.1.0any
xinexine-lib1.1.1any
xinexine-lib1.1.2any
xinexine-lib1.1.3any
xinexine-lib1.1.4any
xinexine-lib1.1.5any
xinexine-lib1.1.6any
xinexine-lib1.1.7any
xinexine-lib1.1.8any
xinexine-lib1.1.9any
xinexine-lib1.1.9.1any
xinexine-lib1.1.10any
xinexine-lib1.1.10.1any
xinexine-lib1.1.11any
xinexine-lib1.1.11.1any
xinexine-lib1.1.12any
xinexine-lib1.1.13any
xinexine-lib1_beta1any
xinexine-lib1_beta2any
xinexine-lib1_beta3any
xinexine-lib1_beta4any
xinexine-lib1_beta5any
xinexine-lib1_beta6any
xinexine-lib1_beta7any
xinexine-lib1_beta8any
xinexine-lib1_beta9any
xinexine-lib1_beta10any
xinexine-lib1_beta11any
xinexine-lib1_beta12any

References 15

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.