CVE-2004-1187

Publication date 10 January 2005

Last updated 24 July 2024


Ubuntu priority

Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.

Status

Package Ubuntu Release Status
xine-lib 7.04 feisty
Fixed 1.1.4-2ubuntu3
6.10 edgy
Fixed 1.1.2+repacked1-0ubuntu3.4
6.06 LTS dapper
Fixed 1.1.1+ubuntu2-7.7