Unrated severityNVD Advisory· Published Jan 11, 2008· Updated Apr 23, 2026
CVE-2008-0238
CVE-2008-0238
Description
Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to execute arbitrary code via the SDP (1) Title, (2) Author, or (3) Copyright attribute, related to the rmff_dump_header function, different vectors than CVE-2008-0225. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- secunia.com/advisories/28384nvdVendor Advisory
- bugs.gentoo.org/show_bug.cginvd
- secunia.com/advisories/28674nvd
- secunia.com/advisories/28955nvd
- secunia.com/advisories/31393nvd
- security.gentoo.org/glsa/glsa-200801-12.xmlnvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.ubuntu.com/usn/usn-635-1nvd
News mentions
0No linked articles in our index yet.