CVE-2009-1274
Publication date 8 April 2009
Last updated 24 July 2024
Ubuntu priority
Integer overflow in the qt_error parse_trak_atom function in demuxers/demux_qt.c in xine-lib 1.1.16.2 and earlier allows remote attackers to execute arbitrary code via a Quicktime movie file with a large count value in an STTS atom, which triggers a heap-based buffer overflow.
Status
Package | Ubuntu Release | Status |
---|---|---|
xine-lib | ||
Notes
mdeslaur
when fixing this, need to also fix a missing part of CVE-2009-0698 http://hg.debian.org/hg/xine-lib/xine-lib/rev/7799748cc0f2
Patch details
Package | Patch details |
---|---|
xine-lib |
References
Related Ubuntu Security Notices (USN)
- USN-763-1
- xine-lib vulnerabilities
- 20 April 2009