ubuntu · CVE-2008-5246

Quick triage

Priority: medium Published: 2008-11-26 01:30:00 UTC Updated: 2024-07-24 15:57:39 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2008-5246 medium priority: Ubuntu including 1 source packages (xine-lib), 5 status rows across 5 suites (dapper, gutsy, hardy, intrepid, upstream): released 4, not-affected 1.

Description:

Multiple heap-based buffer overflows in xine-lib before 1.1.15 allow remote attackers to execute arbitrary code via vectors that send ID3 data to the (1) id3v22_interp_frame and (2) id3v24_interp_frame functions in src/demuxers/id3.c. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

cvelogic Threat Intelligence