diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 354b3da4c76c..46c9fdf0e00a 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -34,6 +34,51 @@ Note: Please add new entries to the beginning of this file. --> + + libxine -- multiple buffer overflow vulnerabilities + + + libxine + 1.1.3 + + + + +

Secunia reports:

+
+

+ Some vulnerabilities have been reported in xine-lib, which + potentially can be exploited by malicious people to compromise + a user's system. +

+

+ 1) A vulnerability is caused due to a boundary error within the + "real_parse_sdp()" function in src/input/libreal/real.c. This + can be exploited to cause a buffer overflow by e.g. tricking a + user into connecting to a malicious server. +

+

+ 2) A buffer overflow exists in the libmms library. + For more information: SA20749 +

+

+ Successful exploitation may allow the execution of arbitrary code. +

+
+ +
+ + CVE-2006-2200 + CVE-2006-6172 + 18608 + 21435 + + + 2006-05-04 + 2006-12-07 + +
+ gnupg -- remotely controllable function pointer