Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.61421
Categoría:Mandrake Local Security Checks
Título:Mandrake Security Advisory MDVSA-2008:178 (xine-lib)
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing an update to xine-lib
announced via advisory MDVSA-2008:178.

Alin Rad Pop found an array index vulnerability in the SDP parser
of xine-lib. If a user or automated system were tricked into opening
a malicious RTSP stream, a remote attacker could possibly execute
arbitrary code with the privileges of the user using the program
(CVE-2008-0073).

The ASF demuxer in xine-lib did not properly check the length of
ASF headers. If a user was tricked into opening a crafted ASF file,
a remote attacker could possibly cause a denial of service or execute
arbitrary code with the privileges of the user using the program
(CVE-2008-1110).

The Matroska demuxer in xine-lib did not properly verify frame sizes,
which could possibly lead to the execution of arbitrary code if a
user opened a crafted ASF file (CVE-2008-1161).

Luigi Auriemma found multiple integer overflows in xine-lib. If a
user was tricked into opening a crafted FLV, MOV, RM, MVE, MKV, or
CAK file, a remote attacker could possibly execute arbitrary code
with the privileges of the user using the program (CVE-2008-1482).

Guido Landi found A stack-based buffer overflow in xine-lib
that could allow a remote attacker to cause a denial of service
(crash) and potentially execute arbitrary code via a long NSF title
(CVE-2008-1878).

The updated packages have been patched to correct this issue.

Affected: 2008.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

https://secure1.securityspace.com/smysecure/catid.html?in=MDVSA-2008:178

Risk factor : Critical

CVSS Score:
9.3

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2008-0073
BugTraq ID: 28312
http://www.securityfocus.com/bid/28312
Debian Security Information: DSA-1536 (Google Search)
http://www.debian.org/security/2008/dsa-1536
Debian Security Information: DSA-1543 (Google Search)
http://www.debian.org/security/2008/dsa-1543
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00456.html
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00143.html
http://security.gentoo.org/glsa/glsa-200804-25.xml
http://security.gentoo.org/glsa/glsa-200808-01.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2008:178
http://www.mandriva.com/security/advisories?name=MDVSA-2008:219
http://secunia.com/secunia_research/2008-10/
http://www.securitytracker.com/id?1019682
http://secunia.com/advisories/28694
http://secunia.com/advisories/29392
http://secunia.com/advisories/29472
http://secunia.com/advisories/29503
http://secunia.com/advisories/29578
http://secunia.com/advisories/29601
http://secunia.com/advisories/29740
http://secunia.com/advisories/29766
http://secunia.com/advisories/29800
http://secunia.com/advisories/30581
http://secunia.com/advisories/31372
http://secunia.com/advisories/31393
http://www.slackware.org/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.392408
SuSE Security Announcement: SUSE-SR:2008:007 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00008.html
SuSE Security Announcement: SUSE-SR:2008:012 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.html
http://www.ubuntu.com/usn/usn-635-1
http://www.vupen.com/english/advisories/2008/0923
http://www.vupen.com/english/advisories/2008/0985
XForce ISS Database: xinelib-sdpplinparse-bo(41339)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41339
Common Vulnerability Exposure (CVE) ID: CVE-2008-1110
https://www.exploit-db.com/exploits/1641
http://security.gentoo.org/glsa/glsa-200802-12.xml
http://secunia.com/advisories/29141
XForce ISS Database: xinelib-demuxasf-bo(41019)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41019
Common Vulnerability Exposure (CVE) ID: CVE-2008-1161
BugTraq ID: 28543
http://www.securityfocus.com/bid/28543
http://secunia.com/advisories/29323
SuSE Security Announcement: SUSE-SR:2008:006 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html
XForce ISS Database: xinelib-demuxer-bo(41172)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41172
Common Vulnerability Exposure (CVE) ID: CVE-2008-1482
BugTraq ID: 28370
http://www.securityfocus.com/bid/28370
Bugtraq: 20080320 Multiple heap overflows in xine-lib 1.1.11 (Google Search)
http://www.securityfocus.com/archive/1/489894/100/0/threaded
Debian Security Information: DSA-1586 (Google Search)
http://www.debian.org/security/2008/dsa-1586
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00157.html
http://aluigi.altervista.org/adv/xinehof-adv.txt
http://aluigi.org/poc/xinehof.zip
http://secunia.com/advisories/29484
http://secunia.com/advisories/29600
http://secunia.com/advisories/29622
http://secunia.com/advisories/29756
http://secunia.com/advisories/30337
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.441137
http://securityreason.com/securityalert/3769
SuSE Security Announcement: SUSE-SR:2008:008 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html
http://www.vupen.com/english/advisories/2008/0981/references
XForce ISS Database: xinelib-multiple-bo(41350)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41350
Common Vulnerability Exposure (CVE) ID: CVE-2008-1878
BugTraq ID: 28816
http://www.securityfocus.com/bid/28816
https://www.exploit-db.com/exploits/5458
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00536.html
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00571.html
http://www.mandriva.com/security/advisories?name=MDVSA-2008:177
http://secunia.com/advisories/29850
http://secunia.com/advisories/30021
http://www.vupen.com/english/advisories/2008/1247/references
XForce ISS Database: xinelib-demuxnsfsendchunk-bo(41865)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41865
CopyrightCopyright (c) 2008 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.