Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-1476
CVE-2004-1476
Description
Stack-based buffer overflow in the VideoCD (VCD) code in xine-lib 1-rc2 through 1-rc5, as derived from libcdio, allows attackers to execute arbitrary code via a VideoCD with an unterminated disk label.
Affected products
17cpe:2.3:o:suse:suse_linux:8.0:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:o:suse:suse_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:8.1:*:*:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:8.2:*:personal:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:9.0:*:personal:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:9.0:*:x86_64:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:9.1:*:personal:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:9.2:*:personal:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.gentoo.org/security/en/glsa/glsa-200409-30.xmlnvdPatchVendor Advisory
- www.securityfocus.com/archive/1/375485/2004-09-02/2004-09-08/0nvdPatchVendor Advisory
- www.securityfocus.com/bid/11206nvdPatch
- xinehq.de/index.php/security/XSA-2004-4nvdPatchVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/17431nvd
News mentions
0No linked articles in our index yet.