Multiple vulnerabilities have been identified in xine-lib, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system.
Integer and heap overflow errors exist in the "parse_block_group()" [demux_matroska.c], "real_parse_audio_specific_data()" [demux_real.c], and "open_ra_file()" [demux_realaudio.c] functions, which could be exploited to crash an affected application or execute arbitrary code.
Various input validation errors exist within the handling of media files (e.g. real), which could be exploited to cause a denial of service.