CVE-2007-0255

critical

Description

XINE 0.99.4 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a certain M3U file that contains a long #EXTINF line and contains format string specifiers in an invalid udp:// URI, possibly a variant of CVE-2007-0017.

References

http://www.securityfocus.com/bid/22252

http://www.securityfocus.com/archive/1/456523/100/0/threaded

http://www.mandriva.com/security/advisories?name=MDKSA-2007:154

http://www.mandriva.com/security/advisories?name=MDKSA-2007:027

http://secunia.com/advisories/23931

http://osvdb.org/31666

Details

Source: Mitre, NVD

Published: 2007-01-16

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical