CVE-2008-0295

Publication date 16 January 2008

Last updated 24 July 2024


Ubuntu priority

Heap-based buffer overflow in modules/access/rtsp/real_sdpplin.c in the Xine library, as used in VideoLAN VLC Media Player 0.8.6d and earlier, allows user-assisted remote attackers to cause a denial of service (crash) or execute arbitrary code via long Session Description Protocol (SDP) data.

Read the notes from the security team

Status

Package Ubuntu Release Status
vlc 9.10 karmic
Fixed 0.8.6e-0ubuntu1
9.04 jaunty
Fixed 0.8.6e-0ubuntu1
8.10 intrepid
Fixed 0.8.6e-0ubuntu1
8.04 LTS hardy
Fixed 0.8.6e-0ubuntu1
7.10 gutsy Ignored end of life, was needed
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life

Notes


jdstrand

per Debian this does not affect xine-lib, just vlc as it ships a really old version