Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long NSF title.
2008-04-17T22:05:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | xine | xine-lib | ≤ 1.1.12 | Yes |
Application | xine | xine-lib | 1.1.0 | Yes |
Application | xine | xine-lib | 1.1.1 | Yes |
Application | xine | xine-lib | 1.1.9 | Yes |
Application | xine | xine-lib | 1.1.10 | Yes |
Application | xine | xine-lib | 1.1.10.1 | Yes |
Application | xine | xine-lib | 1.1.11 | Yes |
Application | xine | xine-lib | 1.1.11.1 | Yes |