Back to Database
Status published
Medium
CVE-2008-5248
xine-lib before 1.1.15 allows remote attackers to cause a denial...
Vulnerability Description
xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via "MP3 files with metadata consisting only of separators."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-5248
Credits & Attribution
No credits recorded in the NVD database.
References
More from xine
View All →CVE-2009-1274
Integer overflow in the qt_error parse_trak_atom function in demuxers/demux_qt.c in...
Medium
5
CVE-2009-0698
Integer overflow in the 4xm demuxer (demuxers/demux_4xm.c) in xine-lib 1.1.16.1...
High
7.5
CVE-2008-5247
The real_parse_audio_specific_data function in demux_real.c in xine-lib 1.1.12, and other...
Medium
4.3
CVE-2008-5246
Multiple heap-based buffer overflows in xine-lib before 1.1.15 allow remote...
Critical
9.3
CVE-2008-5245
xine-lib before 1.1.15 performs V4L video frame preallocation before ascertaining...
Critical
9.3
Affected Vendor
xine
View all reports →Affected Software
xine-lib
Vulnerable Versions:
0, 0.9.13, 1, 1.0, 1.0.1, 1.0.2, 1.0.3a, 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 1.1.9, 1.1.9.1, 1.1.10, 1.1.10.1, 1.1.11, 1.1.11.1, 1.1.12, 1.1.13, 1.1.14, 1_beta1, 1_beta2, 1_beta3, 1_beta4, 1_beta5, 1_beta6, 1_beta7, 1_beta8, 1_beta9, 1_beta10, 1_beta11, 1_beta12
Timeline
Official Publish:
November 26th, 2008
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.