Search

published date: December 31, 2004

CVE-2004-1475 : Stack-based Buffer Overflow Vulnerability

Description

Multiple stack-based buffer overflows in xine-lib 1-rc2 through 1-rc5 allow attackers to execute arbitrary code via (1) long VideoCD vcd:// MRLs or (2) long subtitle lines.

Product(s):

  • Xine Xine-lib 0.99
  • Xine Xine-lib 1_rc2
  • Xine Xine-lib 1_rc3
  • Xine Xine-lib 1_rc4
  • Xine Xine-lib 1_rc5
  • Xine 0.9.18

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2004-1475, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2004-1475 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?