CVE-2008-1878

NameCVE-2008-1878
DescriptionStack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long NSF title.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-1586-1, DTSA-128-1
NVD severityhigh (attack range: remote)
Debian Bugs476990
Debian/oldoldstablenot vulnerable.
Debian/oldstablenot vulnerable.
Debian/stablenot known to be vulnerable.
Debian/testingnot known to be vulnerable.
Debian/unstablenot known to be vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
xine-lib (PTS)squeeze1.1.19-2fixed
wheezy1.1.21-1+deb7u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xine-libsource(unstable)1.1.12-2medium476990
xine-libsourceetch1.1.2+dfsg-7highDSA-1586-1
xine-libsourcelenny1.1.10.1-2+lenny2highDTSA-128-1

Notes

not patched but disabled in testing/unstable

Search for package or bug name: Reporting problems