CVE Vulnerabilities

CVE-2008-0073

Published: Mar 24, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parameter.

Affected Software

NameVendorStart VersionEnd Version
FedoraRedhat8 (including)8 (including)
MplayerUbuntudapper*
MplayerUbuntuedgy*
MplayerUbuntufeisty*
MplayerUbuntugutsy*
MplayerUbuntuhardy*
MplayerUbuntuintrepid*
MplayerUbuntujaunty*
MplayerUbuntukarmic*
VlcUbuntudapper*
VlcUbuntudevel*
VlcUbuntuedgy*
VlcUbuntufeisty*
VlcUbuntugutsy*
VlcUbuntuhardy*
VlcUbuntuintrepid*
VlcUbuntujaunty*
VlcUbuntukarmic*
VlcUbuntulucid*
VlcUbuntumaverick*
VlcUbuntunatty*
VlcUbuntuoneiric*
Xine-libUbuntudapper*
Xine-libUbuntuedgy*
Xine-libUbuntufeisty*
Xine-libUbuntugutsy*
Xine-libUbuntuupstream*

References