>> xine-lib RTSP Data Processing Multiple Buffer Overflow Vulnerabilities
Title : xine-lib RTSP Data Processing Multiple Buffer Overflow Vulnerabilities VUPEN ID : VUPEN/ADV-2008-0163 CVE ID : CVE-2008-0225 - CVE-2008-0225
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-01-16
Technical Description
Multiple vulnerabilities have been identified in xine-lib, which could be exploited by attackers to cause a denial of service or execute arbitrary code. These issues are caused by buffer overflow errors in various functions within the "src/input/libreal/rmff.c" file when processing malformed RTSP / SDP data, which could be exploited by attackers to crash a vulnerable application or compromise an affected system via a specially crafted stream.