xine-lib Multiple Unspecified Remote Denial of Service Vulnerabilities
BID:27251
Info
xine-lib Multiple Unspecified Remote Denial of Service Vulnerabilities
| Bugtraq ID: | 27251 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 11 2008 12:00AM |
| Updated: | Jan 14 2008 06:58PM |
| Credit: | Sam Hocevar discovered these vulnerabilities. |
| Vulnerable: |
xine xine-lib 1.1.9 xine xine-lib 1.1.4 xine xine-lib 1.1.3 xine xine-lib 1.1.2 xine xine-lib 1.1.1 xine xine-lib 1.1 xine xine-lib 1.0.2 xine xine-lib 1.0.1 xine xine-lib 1.0 xine xine-lib 0.99 xine xine-lib 0.9.13 xine xine-lib 0.9.8 xine xine-lib 0.9.8 xine xine-lib 1-rc8 xine xine-lib 1-rc7 xine xine-lib 1-rc6a xine xine-lib 1-rc6 xine xine-lib 1-rc5 xine xine-lib 1-rc4 xine xine-lib 1-rc3c xine xine-lib 1-rc3b xine xine-lib 1-rc3a xine xine-lib 1-rc3 xine xine-lib 1-rc2 xine xine-lib 1-rc1 xine xine-lib 1-rc0 xine xine-lib 1-beta9 xine xine-lib 1-beta8 xine xine-lib 1-beta7 xine xine-lib 1-beta6 xine xine-lib 1-beta5 xine xine-lib 1-beta4 xine xine-lib 1-beta3 xine xine-lib 1-beta2 xine xine-lib 1-beta12 xine xine-lib 1-beta11 xine xine-lib 1-beta10 xine xine-lib 1-beta1 xine xine-lib 1-alpha |
| Not Vulnerable: | |
Discussion
xine-lib Multiple Unspecified Remote Denial of Service Vulnerabilities
The 'xine-lib' library is prone to multiple unspecified denial-of-service vulnerabilities when handling malformed media files.
An attacker can exploit these issues to crash the affected application using the library, denying service to legitimate users.
The 'xine-lib' library is prone to multiple unspecified denial-of-service vulnerabilities when handling malformed media files.
An attacker can exploit these issues to crash the affected application using the library, denying service to legitimate users.
Exploit / POC
xine-lib Multiple Unspecified Remote Denial of Service Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting user to open a malicious media file.
The 'zzuf' fuzzing tool demonstrates these issues. The tool is available from the following site:
http://sam.zoy.org/zzuf/
To exploit these issues, an attacker must entice an unsuspecting user to open a malicious media file.
The 'zzuf' fuzzing tool demonstrates these issues. The tool is available from the following site:
http://sam.zoy.org/zzuf/
Solution / Fix
xine-lib Multiple Unspecified Remote Denial of Service Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
xine-lib Multiple Unspecified Remote Denial of Service Vulnerabilities
References:
References:
- How long does it take to fix a crash-bug? (Hanno Bock)
- xine Homepage (xine)
- re-resting of zzuf results (Hanno Böck
)