xine-lib before 1.1.15 performs V4L video frame preallocation before ascertaining the required length, which has unknown impact and attack vectors, possibly related to a buffer overflow in the open_video_capture_device function in src/input/input_v4l.c.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade media-libs/xine-lib. | Oct 30, 2017 | Nov 25, 2008 |
| Suse | — | Upgrade xine-lib-64bitUpgrade xine-extraUpgrade xine-libUpgrade xine-uiUpgrade xine-lib-32bitUpgrade xine-develUpgrade xine-lib-x86 | Feb 17, 2015 | Nov 25, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub