Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2006-1905

Опубликовано: 20 апр. 2006
Источник: debian
EPSS Низкий

Описание

Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote attackers to execute arbitrary code via format string specifiers in a long filename on an EXTINFO line in a playlist file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xine-uifixed0.99.4-1package

Примечания

  • This is a non-issue: An attacker would need to trick the user into opening

  • an MP3 file with a very obviously manipulated filename containing the shellcode

EPSS

Процентиль: 92%
0.07959
Низкий

Связанные уязвимости

ubuntu
больше 19 лет назад

Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote attackers to execute arbitrary code via format string specifiers in a long filename on an EXTINFO line in a playlist file.

nvd
больше 19 лет назад

Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote attackers to execute arbitrary code via format string specifiers in a long filename on an EXTINFO line in a playlist file.

github
больше 3 лет назад

Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote attackers to execute arbitrary code via format string specifiers in a long filename on an EXTINFO line in a playlist file.

EPSS

Процентиль: 92%
0.07959
Низкий