Opened 17 years ago
Closed 17 years ago
#1042 closed defect (fixed)
Possible Array Indexing Vulnerability which lets injecting code in sdpplin_parse()
Reported by: | Owned by: | ||
---|---|---|---|
Priority: | important | Component: | streaming |
Version: | unspecified | Severity: | critical |
Keywords: | Cc: | ||
Blocked By: | Blocking: | ||
Reproduced by developer: | no | Analyzed by developer: | no |
Description
Secunia has just released an advisory [0] for xine-lib telling that RTSP streams can be used to inject a code. Xine developers have fixed it and the url of commit for it is [1].
The same code lies in MPlayer too and there could be a security flaw.
Note:
See TracTickets
for help on using tickets.
This is fixed by Reimar in svn r26299