← Back

CVE-2008-5247

nvd nist
Published: Nov 26, 2008Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The real_parse_audio_specific_data function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, uses an untrusted height (aka codec_data_length) value as a divisor, which allow remote attackers to cause a denial of service (divide-by-zero error and crash) via a zero value.

Affected (49)

Products: Xine: Xine Lib
1 product
Xine Lib
Configuration A
49 vulnerable
Vulnerable SoftwareAffected Versions
Xine
Up to 1.1.15
Version 0.9.13
Version 1.0.1
Version 1.0.2
Version 1.0.3a
Version 1.0
Version 1.1.0
Version 1.1.10.1
Version 1.1.10
Version 1.1.11.1
Version 1.1.11
Version 1.1.12
Version 1.1.13
Version 1.1.14
Version 1.1.1
Version 1.1.2
Version 1.1.3
Version 1.1.4
Version 1.1.5
Version 1.1.6
Version 1.1.7
Version 1.1.8
Version 1.1.9.1
Version 1.1.9
Version 1 rc0a
Version 1 rc1
Version 1 rc2
Version 1 rc3
Version 1 rc3a
Version 1 rc3b
Version 1 rc3c
Version 1 rc4
Version 1 rc4a
Version 1 rc5
Version 1 rc6a
Version 1 rc7
Version 1 rc8
Version 1_beta10
Version 1_beta11
Version 1_beta12
Version 1_beta1
Version 1_beta2
Version 1_beta3
Version 1_beta4
Version 1_beta5
Version 1_beta6
Version 1_beta7
Version 1_beta8
Version 1_beta9

Related CWEs

Timeline

No history available yet.