CVE-2008-0486
CVE-2008-0486
Array index vulnerability in libmpdemux/demux_audio.c in MPlayer 1.0rc2 and SVN before r25917, and possibly earlier versions, as used in Xine-lib 1.1.10, might allow remote attackers to execute arbitrary code via a crafted FLAC tag, which triggers a buffer overflow.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://bugs.gentoo.org/show_bug.cgi?id=209106http://bugs.xine-project.org/show_bug.cgi?id=38http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=431541http://secunia.com/advisories/28779http://secunia.com/advisories/28801http://secunia.com/advisories/28918http://secunia.com/advisories/28955http://secunia.com/advisories/28956http://secunia.com/advisories/28989http://secunia.com/advisories/29141