|
Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2007:027: xine-ui Vulnerability Scan
Vulnerability Scan Summary Check for the version of the xine-ui package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2007:027 (xine-ui).
Format string vulnerability in the errors_create_window function in
errors.c in xine-ui allows attackers to execute arbitrary code via
unknown vectors. (CVE-2007-0254)
XINE 0.99.4 allows user-assisted remote attackers to cause a denial of
service (application crash) and possibly execute arbitrary code via a
certain M3U file that contains a long #EXTINF line and contains format
string specifiers in an invalid udp:// URI, possibly a variant of
CVE-2007-0017. (CVE-2007-0255)
The updated packages have been patched to correct these issues.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2007:027
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|