CVE-2008-5242

demux_qt.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, does not validate the count field before calling calloc for STSD_ATOM atom allocation, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted media file.

Published: 2008-11-26 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2008-5242 is rated Moderate Risk (53.3/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.05%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2008-5242

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-03-19 1.26% 1.05% -0.20%
2 2025-03-17 2.97% 1.26% -1.71%
3 2024-12-02 2.97%

Full EPSS history (5 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2008-5242

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.8 2.0 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
8.6 6.4 [email protected]

Weakness enumeration for CVE-2008-5242

OS Trackers for CVE-2008-5242

vendor priority summary link
gentoo normal CVE-2008-5242: 1 GLSA(s) (201006-04), 1 atom(s) (media-libs/xine-lib); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2008-5242
ubuntu medium CVE-2008-5242 medium priority: Ubuntu including 1 source packages (xine-lib), 5 status rows across 5 suites (dapper, gutsy, hardy, intrepid, upstream): released 4, needs-triage 1. https://ubuntu.com/security/CVE-2008-5242

Affected software / configurations for CVE-2008-5242

Vendor Product Version Raw CPE
xine xine-lib <= 1.1.15 cpe:2.3:a:xine:xine-lib:*:*:*:*:*:*:*:*
xine xine-lib 0.9.13 cpe:2.3:a:xine:xine-lib:0.9.13:*:*:*:*:*:*:*
xine xine-lib 1 cpe:2.3:a:xine:xine-lib:1:rc0a:*:*:*:*:*:*
xine xine-lib 1 cpe:2.3:a:xine:xine-lib:1:rc1:*:*:*:*:*:*
xine xine-lib 1 cpe:2.3:a:xine:xine-lib:1:rc2:*:*:*:*:*:*
xine xine-lib 1 cpe:2.3:a:xine:xine-lib:1:rc3:*:*:*:*:*:*
xine xine-lib 1 cpe:2.3:a:xine:xine-lib:1:rc3a:*:*:*:*:*:*
xine xine-lib 1 cpe:2.3:a:xine:xine-lib:1:rc3b:*:*:*:*:*:*
xine xine-lib 1 cpe:2.3:a:xine:xine-lib:1:rc3c:*:*:*:*:*:*
xine xine-lib 1 cpe:2.3:a:xine:xine-lib:1:rc4:*:*:*:*:*:*
xine xine-lib 1 cpe:2.3:a:xine:xine-lib:1:rc4a:*:*:*:*:*:*
xine xine-lib 1 cpe:2.3:a:xine:xine-lib:1:rc5:*:*:*:*:*:*
xine xine-lib 1 cpe:2.3:a:xine:xine-lib:1:rc6a:*:*:*:*:*:*
xine xine-lib 1 cpe:2.3:a:xine:xine-lib:1:rc7:*:*:*:*:*:*
xine xine-lib 1 cpe:2.3:a:xine:xine-lib:1:rc8:*:*:*:*:*:*
xine xine-lib 1.0 cpe:2.3:a:xine:xine-lib:1.0:*:*:*:*:*:*:*
xine xine-lib 1.0.1 cpe:2.3:a:xine:xine-lib:1.0.1:*:*:*:*:*:*:*
xine xine-lib 1.0.2 cpe:2.3:a:xine:xine-lib:1.0.2:*:*:*:*:*:*:*
xine xine-lib 1.0.3a cpe:2.3:a:xine:xine-lib:1.0.3a:*:*:*:*:*:*:*
xine xine-lib 1.1.0 cpe:2.3:a:xine:xine-lib:1.1.0:*:*:*:*:*:*:*
xine xine-lib 1.1.1 cpe:2.3:a:xine:xine-lib:1.1.1:*:*:*:*:*:*:*
xine xine-lib 1.1.2 cpe:2.3:a:xine:xine-lib:1.1.2:*:*:*:*:*:*:*
xine xine-lib 1.1.3 cpe:2.3:a:xine:xine-lib:1.1.3:*:*:*:*:*:*:*
xine xine-lib 1.1.4 cpe:2.3:a:xine:xine-lib:1.1.4:*:*:*:*:*:*:*
xine xine-lib 1.1.5 cpe:2.3:a:xine:xine-lib:1.1.5:*:*:*:*:*:*:*
xine xine-lib 1.1.6 cpe:2.3:a:xine:xine-lib:1.1.6:*:*:*:*:*:*:*
xine xine-lib 1.1.7 cpe:2.3:a:xine:xine-lib:1.1.7:*:*:*:*:*:*:*
xine xine-lib 1.1.8 cpe:2.3:a:xine:xine-lib:1.1.8:*:*:*:*:*:*:*
xine xine-lib 1.1.9 cpe:2.3:a:xine:xine-lib:1.1.9:*:*:*:*:*:*:*
xine xine-lib 1.1.9.1 cpe:2.3:a:xine:xine-lib:1.1.9.1:*:*:*:*:*:*:*
xine xine-lib 1.1.10 cpe:2.3:a:xine:xine-lib:1.1.10:*:*:*:*:*:*:*
xine xine-lib 1.1.10.1 cpe:2.3:a:xine:xine-lib:1.1.10.1:*:*:*:*:*:*:*
xine xine-lib 1.1.11 cpe:2.3:a:xine:xine-lib:1.1.11:*:*:*:*:*:*:*
xine xine-lib 1.1.11.1 cpe:2.3:a:xine:xine-lib:1.1.11.1:*:*:*:*:*:*:*
xine xine-lib 1.1.12 cpe:2.3:a:xine:xine-lib:1.1.12:*:*:*:*:*:*:*
xine xine-lib 1.1.13 cpe:2.3:a:xine:xine-lib:1.1.13:*:*:*:*:*:*:*
xine xine-lib 1.1.14 cpe:2.3:a:xine:xine-lib:1.1.14:*:*:*:*:*:*:*
xine xine-lib 1_beta1 cpe:2.3:a:xine:xine-lib:1_beta1:*:*:*:*:*:*:*
xine xine-lib 1_beta2 cpe:2.3:a:xine:xine-lib:1_beta2:*:*:*:*:*:*:*
xine xine-lib 1_beta3 cpe:2.3:a:xine:xine-lib:1_beta3:*:*:*:*:*:*:*
xine xine-lib 1_beta4 cpe:2.3:a:xine:xine-lib:1_beta4:*:*:*:*:*:*:*
xine xine-lib 1_beta5 cpe:2.3:a:xine:xine-lib:1_beta5:*:*:*:*:*:*:*
xine xine-lib 1_beta6 cpe:2.3:a:xine:xine-lib:1_beta6:*:*:*:*:*:*:*
xine xine-lib 1_beta7 cpe:2.3:a:xine:xine-lib:1_beta7:*:*:*:*:*:*:*
xine xine-lib 1_beta8 cpe:2.3:a:xine:xine-lib:1_beta8:*:*:*:*:*:*:*
xine xine-lib 1_beta9 cpe:2.3:a:xine:xine-lib:1_beta9:*:*:*:*:*:*:*
xine xine-lib 1_beta10 cpe:2.3:a:xine:xine-lib:1_beta10:*:*:*:*:*:*:*
xine xine-lib 1_beta11 cpe:2.3:a:xine:xine-lib:1_beta11:*:*:*:*:*:*:*
xine xine-lib 1_beta12 cpe:2.3:a:xine:xine-lib:1_beta12:*:*:*:*:*:*:*

References for CVE-2008-5242

cvelogic Threat Intelligence