Ubuntu Security Notice (C) 2005-2015 Canonical, Inc. / NASL script (C) 2006-2015 Tenable Network Security, Inc.
The remote Ubuntu host is missing one or more security-related patches.
Ulf Harnhammar discovered a format string vulnerability in the CDDB
module's cache file handling in the Xine library, which is used by
packages such as xine-ui, totem-xine, and gxine.
By tricking an user into playing a particular audio CD which has a
specially crafted CDDB entry, a remote attacker could exploit this
vulnerability to execute arbitrary code with the privileges of the
user running the application. Since CDDB servers usually allow anybody
to add and modify information, this exploit does not even require a
particular CDDB server to be selected.
Update the affected libxine-dev and / or libxine1 packages.
Risk factor :
High / CVSS Base Score : 7.5
CVSS Temporal Score : 6.5
Public Exploit Available : false
Family: Ubuntu Local Security Checks
Nessus Plugin ID: 20610 ()
Bugtraq ID: 15044
CVE ID: CVE-2005-2337CVE-2005-2967
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.