Upstream information
Description
Multiple integer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) crafted width and height values that are not validated by the mymng_process_header function in demux_mng.c before use in an allocation calculation or (2) crafted current_atom_size and string_size values processed by the parse_reference_atom function in demux_qt.c for an RDRF_ATOM string.NVD CVSS v2 Base Score: 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Novell/SUSE information
Novell Bugzilla entry: 419541 SUSE Security Advisories:- SUSE-SR:2009:004, published Tue, 17 Feb 2009 10:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Linux Enterprise SDK 10 SP2 |
| sle10-sp2-sdk.s390x sle10-sp2-sdk.x86 sled10-sp2.x86-64 sle10-sp2-sdk.ppc sle10-sp2-sdk.x86-64 sled10-sp2.x86 sle10-sp2-sdk.ia64 ZYPP Patch Nr: 5965 |
| SUSE Linux Enterprise SDK 10 SP2 |
| sle10-sp2-sdk.s390x sle10-sp2-sdk.x86 sled10-sp2.x86-64 sle10-sp2-sdk.ppc sle10-sp2-sdk.x86-64 sled10-sp2.x86 sle10-sp2-sdk.ia64 ZYPP Patch Nr: 5965 |
| SUSE Linux Enterprise SDK 10 SP2 |
| sle10-sp2-sdk.s390x sle10-sp2-sdk.x86 sled10-sp2.x86-64 sle10-sp2-sdk.ppc sle10-sp2-sdk.x86-64 sled10-sp2.x86 sle10-sp2-sdk.ia64 ZYPP Patch Nr: 5965 |
| SUSE Linux Enterprise SDK 10 SP2 |
| sle10-sp2-sdk.s390x sle10-sp2-sdk.x86 sled10-sp2.x86-64 sle10-sp2-sdk.ppc sle10-sp2-sdk.x86-64 sled10-sp2.x86 sle10-sp2-sdk.ia64 ZYPP Patch Nr: 5965 |
| openSUSE 11.0 |
| |
| openSUSE 11.0 |
| |
| Novell Linux Desktop 9 for x86 |
| sles9-nld.x86-64 core9.x86-64 core9.s390 sles9-nld.x86 core9.x86 sles9-nld.x86 sles9-nld.x86-64 core9.ppc core9.s390x core9.ia64 YOU Patch Nr: 12346 |
| Novell Linux Desktop 9 for x86_64 |
| sles9-nld.x86-64 core9.x86-64 core9.s390 sles9-nld.x86 core9.x86 sles9-nld.x86 sles9-nld.x86-64 core9.ppc core9.s390x core9.ia64 YOU Patch Nr: 12346 |
| SLES SDK 9 for IPF |
| sles9-nld.x86-64 core9.x86-64 core9.s390 sles9-nld.x86 core9.x86 sles9-nld.x86 sles9-nld.x86-64 core9.ppc core9.s390x core9.ia64 YOU Patch Nr: 12346 |
| SLES SDK 9 for IBM iSeries and IBM pSeries |
| sles9-nld.x86-64 core9.x86-64 core9.s390 sles9-nld.x86 core9.x86 sles9-nld.x86 sles9-nld.x86-64 core9.ppc core9.s390x core9.ia64 YOU Patch Nr: 12346 |
| Novell Linux Desktop 9 SDK for x86 SLES SDK 9 for IBM S/390 and IBM zSeries SLES SDK 9 for x86 |
| sles9-nld.x86-64 core9.x86-64 core9.s390 sles9-nld.x86 core9.x86 sles9-nld.x86 sles9-nld.x86-64 core9.ppc core9.s390x core9.ia64 YOU Patch Nr: 12346 |
| SLES SDK 9 for IBM zSeries |
| sles9-nld.x86-64 core9.x86-64 core9.s390 sles9-nld.x86 core9.x86 sles9-nld.x86 sles9-nld.x86-64 core9.ppc core9.s390x core9.ia64 YOU Patch Nr: 12346 |
| Novell Linux Desktop 9 SDK for x86_64 SLES SDK 9 for X86-64 |
| sles9-nld.x86-64 core9.x86-64 core9.s390 sles9-nld.x86 core9.x86 sles9-nld.x86 sles9-nld.x86-64 core9.ppc core9.s390x core9.ia64 YOU Patch Nr: 12346 |
