|
Mandriva- Advisories MDVSA-2008:046: Updated xine-lib package fixes arbitrary code execution vulnerability
Advisories MDVSA-2008:046: Updated xine-lib package fixes arbitrary code execution vulnerability
An array index vulnerability found in the FLAC audio demuxer might allow remote attackers to execute arbitrary code via a crafted FLAC tag, which triggers a buffer overflow. Although originally an MPlayer issue, it also affects xine-lib due to code similarity. The updated packages have been patched to prevent this issue.
http://mandrivausers.org/index.php?showtopic=49844
http://mandrivausers.org/index.php?showtopic=49844
Fri, 15 Feb 2008 23:47:02 +0000
|