mirror of
https://git.FreeBSD.org/ports.git
synced 2025-02-07 11:49:40 +00:00
For libxine -- format string vulnerability entry:
- Add reference to xine security announcement. - Fix indention on a few lines.
This commit is contained in:
parent
eb338f5115
commit
0fd61e032b
Notes:
svn2git
2021-03-31 03:12:20 +00:00
svn path=/head/; revision=144713
@ -47,17 +47,18 @@ Note: Please add new entries to the beginning of this file.
|
||||
<p>Gentoo Linux Security Advisory reports:</p>
|
||||
<blockquote cite="http://www.gentoo.org/security/en/glsa/glsa-200510-08.xml">
|
||||
<p>Ulf Harnhammar discovered a format string bug in the routines
|
||||
handling CDDB server response contents.</p>
|
||||
<p>An attacker could submit malicious information about an audio
|
||||
CD to a public CDDB server (or impersonate a public CDDB server).
|
||||
When the victim plays this CD on a multimedia frontend relying
|
||||
on xine-lib, it could end up executing arbitrary code.</p>
|
||||
handling CDDB server response contents.</p>
|
||||
<p>An attacker could submit malicious information about an audio
|
||||
CD to a public CDDB server (or impersonate a public CDDB server).
|
||||
When the victim plays this CD on a multimedia frontend relying
|
||||
on xine-lib, it could end up executing arbitrary code.</p>
|
||||
</blockquote>
|
||||
</body>
|
||||
</description>
|
||||
<references>
|
||||
<cvename>CAN-2005-2967</cvename>
|
||||
<url>http://www.gentoo.org/security/en/glsa/glsa-200510-08.xml</url>
|
||||
<url>http://xinehq.de/index.php/security/XSA-2005-1</url>
|
||||
</references>
|
||||
<dates>
|
||||
<discovery>2005-10-08</discovery>
|
||||
|
Loading…
x
Reference in New Issue
Block a user