Quoting:
"Heap-based buffer overflow in the rmff_dump_cont function in
input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote
attackers to execute arbitrary code via the SDP Abstract attribute,
related to the rmff_dump_header function and related to disregarding
the max field. (CVE-2008-0225)
Multiple heap-based buffer overflows in the rmff_dump_cont function
in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers
to execute arbitrary code via the SDP (1) Title, (2) Author, or
(3) Copyright attribute, related to the rmff_dump_header function,
different vectors than CVE-2008-0225. (CVE-2008-0238)"
See also: www.mandriva. com/en/ security/ advisories? name=MDVSA- 2008:020)
MDVSA-2008:020 (http://
Quoting: rmff.c in xine-lib 1.1.9 and earlier allows remote
"Heap-based buffer overflow in the rmff_dump_cont function in
input/libreal/
attackers to execute arbitrary code via the SDP Abstract attribute,
related to the rmff_dump_header function and related to disregarding
the max field. (CVE-2008-0225)
Multiple heap-based buffer overflows in the rmff_dump_cont function rmff.c in xine-lib 1.1.9 allow remote attackers
in input/libreal/
to execute arbitrary code via the SDP (1) Title, (2) Author, or
(3) Copyright attribute, related to the rmff_dump_header function,
different vectors than CVE-2008-0225. (CVE-2008-0238)"