CVE-2008-5247

NONE EPSS 71.4%
Published Nov 26, 200817y ago · Modified Jun 16, 20262w ago
Find Similar
Published Nov 26, 2008 17y ago
Last Modified Jun 16, 2026 2w ago

Description

The real_parse_audio_specific_data function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, uses an untrusted height (aka codec_data_length) value as a divisor, which allow remote attackers to cause a denial of service (divide-by-zero error and crash) via a zero value.

Threat Intelligence

EPSS Exploit Probability
71.4% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-189

Affected Products 49

VendorProductVersionRange
xinexine-lib* ≤1.1.15
xinexine-lib0.9.13any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1.0any
xinexine-lib1.0.1any
xinexine-lib1.0.2any
xinexine-lib1.0.3aany
xinexine-lib1.1.0any
xinexine-lib1.1.1any
xinexine-lib1.1.2any
xinexine-lib1.1.3any
xinexine-lib1.1.4any
xinexine-lib1.1.5any
xinexine-lib1.1.6any
xinexine-lib1.1.7any
xinexine-lib1.1.8any
xinexine-lib1.1.9any
xinexine-lib1.1.9.1any
xinexine-lib1.1.10any
xinexine-lib1.1.10.1any
xinexine-lib1.1.11any
xinexine-lib1.1.11.1any
xinexine-lib1.1.12any
xinexine-lib1.1.13any
xinexine-lib1.1.14any
xinexine-lib1_beta1any
xinexine-lib1_beta2any
xinexine-lib1_beta3any
xinexine-lib1_beta4any
xinexine-lib1_beta5any
xinexine-lib1_beta6any
xinexine-lib1_beta7any
xinexine-lib1_beta8any
xinexine-lib1_beta9any
xinexine-lib1_beta10any
xinexine-lib1_beta11any
xinexine-lib1_beta12any

References 8

  • lists.opensuse.org http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
  • secunia.com http://secunia.com/advisories/31827
  • securityreason.com http://securityreason.com/securityalert/4648
  • ocert.org http://www.ocert.org/analysis/2008-008/analysis.txt
  • securityfocus.com http://www.securityfocus.com/archive/1/495674/100/0/threaded
  • securityfocus.com http://www.securityfocus.com/bid/30797
  • redhat.com https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00174.html
  • redhat.com https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00385.html

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.