CVE-2008-5242

NONE EPSS 86.3%
Published Nov 26, 200817y ago · Modified Jun 16, 20262w ago
Find Similar
Published Nov 26, 2008 17y ago
Last Modified Jun 16, 2026 2w ago

Description

demux_qt.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, does not validate the count field before calling calloc for STSD_ATOM atom allocation, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted media file.

Threat Intelligence

EPSS Exploit Probability
86.3% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer Memory Safety

Affected Products 49

VendorProductVersionRange
xinexine-lib* ≤1.1.15
xinexine-lib0.9.13any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1.0any
xinexine-lib1.0.1any
xinexine-lib1.0.2any
xinexine-lib1.0.3aany
xinexine-lib1.1.0any
xinexine-lib1.1.1any
xinexine-lib1.1.2any
xinexine-lib1.1.3any
xinexine-lib1.1.4any
xinexine-lib1.1.5any
xinexine-lib1.1.6any
xinexine-lib1.1.7any
xinexine-lib1.1.8any
xinexine-lib1.1.9any
xinexine-lib1.1.9.1any
xinexine-lib1.1.10any
xinexine-lib1.1.10.1any
xinexine-lib1.1.11any
xinexine-lib1.1.11.1any
xinexine-lib1.1.12any
xinexine-lib1.1.13any
xinexine-lib1.1.14any
xinexine-lib1_beta1any
xinexine-lib1_beta2any
xinexine-lib1_beta3any
xinexine-lib1_beta4any
xinexine-lib1_beta5any
xinexine-lib1_beta6any
xinexine-lib1_beta7any
xinexine-lib1_beta8any
xinexine-lib1_beta9any
xinexine-lib1_beta10any
xinexine-lib1_beta11any
xinexine-lib1_beta12any

References 9

  • lists.opensuse.org http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
  • secunia.com http://secunia.com/advisories/31827
  • securityreason.com http://securityreason.com/securityalert/4648
  • ocert.org http://www.ocert.org/analysis/2008-008/analysis.txt
  • securityfocus.com http://www.securityfocus.com/archive/1/495674/100/0/threaded
  • securityfocus.com http://www.securityfocus.com/bid/30797
    Patch
  • exchange.xforce.ibmcloud.com https://exchange.xforce.ibmcloud.com/vulnerabilities/44657
  • redhat.com https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00174.html
  • redhat.com https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00385.html

Remediation