Details
The real_parse_headers function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, relies on an untrusted input length value to "reindex into an allocated buffer," which allows remote attackers to cause a denial of service (crash) via a crafted value, probably an array index error.Novell Bugzilla entry: 419541 SUSE Security Advisories:
- SUSE-SR:2009:004, published Tue, 17 Feb 2009 10:00:00 +0000
- SUSE-SR:2009:004 , published Tue, 17 Feb 2009 10:00:00 +0000
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Linux Enterprise Desktop 10 SP2 for x86 |
| sles10-sp2-sdk. s390x sles10-sp2-sdk. x86 sled10-sp2. x86-64 sles10-sp2-sdk. ppc sles10-sp2-sdk. x86-64 sled10-sp2. x86 sles10-sp2-sdk. ia64 ZYPP Patch Nr: 5965 |
| SUSE Linux Enterprise Desktop 10 SP2 for AMD64 and Intel EM64T |
| sles10-sp2-sdk. s390x sles10-sp2-sdk. x86 sled10-sp2. x86-64 sles10-sp2-sdk. ppc sles10-sp2-sdk. x86-64 sled10-sp2. x86 sles10-sp2-sdk. ia64 ZYPP Patch Nr: 5965 |
| SLE SDK 10 SP2 for x86 |
| sles10-sp2-sdk. s390x sles10-sp2-sdk. x86 sled10-sp2. x86-64 sles10-sp2-sdk. ppc sles10-sp2-sdk. x86-64 sled10-sp2. x86 sles10-sp2-sdk. ia64 ZYPP Patch Nr: 5965 |
| SLE SDK 10 SP2 for IPF |
| sles10-sp2-sdk. s390x sles10-sp2-sdk. x86 sled10-sp2. x86-64 sles10-sp2-sdk. ppc sles10-sp2-sdk. x86-64 sled10-sp2. x86 sles10-sp2-sdk. ia64 ZYPP Patch Nr: 5965 |
| SLE SDK 10 SP2 for IBM iSeries and IBM pSeries |
| sles10-sp2-sdk. s390x sles10-sp2-sdk. x86 sled10-sp2. x86-64 sles10-sp2-sdk. ppc sles10-sp2-sdk. x86-64 sled10-sp2. x86 sles10-sp2-sdk. ia64 ZYPP Patch Nr: 5965 |
| SLE SDK 10 SP2 for IBM zSeries SLE SDK 10 SP2 for X86-64 |
| sles10-sp2-sdk. s390x sles10-sp2-sdk. x86 sled10-sp2. x86-64 sles10-sp2-sdk. ppc sles10-sp2-sdk. x86-64 sled10-sp2. x86 sles10-sp2-sdk. ia64 ZYPP Patch Nr: 5965 |
| openSUSE 10.3 |
| ZYPP Patch Nr: 5966 SAT Patch Nr: 483 |
| openSUSE 11.0 |
| ZYPP Patch Nr: 5966 SAT Patch Nr: 483 |
| openSUSE 11.0 |
| ZYPP Patch Nr: 5966 SAT Patch Nr: 483 |
| Novell Linux Desktop 9 for x86 |
| sles9-nld. x86-64 core9. x86-64 core9. s390 sles9-nld. x86 core9. x86 sles9-nld. x86 sles9-nld. x86-64 core9. ppc core9. s390x core9. ia64 YOU Patch Nr: 12346 |
| Novell Linux Desktop 9 for x86_64 |
| sles9-nld. x86-64 core9. x86-64 core9. s390 sles9-nld. x86 core9. x86 sles9-nld. x86 sles9-nld. x86-64 core9. ppc core9. s390x core9. ia64 YOU Patch Nr: 12346 |
| SLES SDK 9 for IPF |
| sles9-nld. x86-64 core9. x86-64 core9. s390 sles9-nld. x86 core9. x86 sles9-nld. x86 sles9-nld. x86-64 core9. ppc core9. s390x core9. ia64 YOU Patch Nr: 12346 |
| SLES SDK 9 for IBM iSeries and IBM pSeries |
| sles9-nld. x86-64 core9. x86-64 core9. s390 sles9-nld. x86 core9. x86 sles9-nld. x86 sles9-nld. x86-64 core9. ppc core9. s390x core9. ia64 YOU Patch Nr: 12346 |
| Novell Linux Desktop 9 SDK for x86 SLES SDK 9 for IBM S/390 and IBM zSeries SLES SDK 9 for x86 |
| sles9-nld. x86-64 core9. x86-64 core9. s390 sles9-nld. x86 core9. x86 sles9-nld. x86 sles9-nld. x86-64 core9. ppc core9. s390x core9. ia64 YOU Patch Nr: 12346 |
| SLES SDK 9 for IBM zSeries |
| sles9-nld. x86-64 core9. x86-64 core9. s390 sles9-nld. x86 core9. x86 sles9-nld. x86 sles9-nld. x86-64 core9. ppc core9. s390x core9. ia64 YOU Patch Nr: 12346 |
| Novell Linux Desktop 9 SDK for x86_64 SLES SDK 9 for X86-64 |
| sles9-nld. x86-64 core9. x86-64 core9. s390 sles9-nld. x86 core9. x86 sles9-nld. x86 sles9-nld. x86-64 core9. ppc core9. s390x core9. ia64 YOU Patch Nr: 12346 |