Ubuntu 4.10 / 5.04 : xine-lib vulnerability (USN-196-1)

Ubuntu Security Notice (C) 2005-2014 Canonical, Inc. / NASL script (C) 2006-2014 Tenable Network Security, Inc.


Synopsis :

The remote Ubuntu host is missing one or more security-related patches.

Description :

Ulf Harnhammar discovered a format string vulnerability in the CDDB
module's cache file handling in the Xine library, which is used by
packages such as xine-ui, totem-xine, and gxine.

By tricking an user into playing a particular audio CD which has a
specially crafted CDDB entry, a remote attacker could exploit this
vulnerability to execute arbitrary code with the privileges of the
user running the application. Since CDDB servers usually allow anybody
to add and modify information, this exploit does not even require a
particular CDDB server to be selected.

Solution :

Update the affected libxine-dev and / or libxine1 packages.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)

Family: Ubuntu Local Security Checks

Nessus Plugin ID: 20610 ()

Bugtraq ID:

CVE ID: CVE-2005-2337
CVE-2005-2967