Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
Slackware Advisory SSA:2005-283-01 xine-lib
Information
Severity
Severity
Medium
Family
Family
Slackware Local Security Checks
CVSSv2 Base
CVSSv2 Base
6.5
CVSSv2 Vector
CVSSv2 Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Solution Type
Solution Type
Vendor Patch
Created
Created
11 years ago
Modified
Modified
5 years ago
Summary
The remote host is missing an update as announced via advisory SSA:2005-283-01.
Insight
Insight
New xine-lib packages are available for Slackware 9.1, 10.0, 10.1, 10.2, and -current to fix a security issue. A format string bug may allow the execution of arbitrary code as the user running a xine-lib linked application. The attacker must provide (by uploading or running a server) specially crafted CDDB information and then get the user to play the referenced audio CD.
Solution
Solution
Upgrade to the new package(s).