Total vulnerabilities in the database
xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options in an MRL link.
Software | From | Fixed in |
---|---|---|
xine / xine | 1_beta9 | 1_beta9.x |
xine / xine | 1_beta3 | 1_beta3.x |
xine / xine | 1_rc0a | 1_rc0a.x |
xine / xine-lib | 1_rc3b | 1_rc3b.x |
xine / xine | 1_beta4 | 1_beta4.x |
xine / xine | 1_rc3b | 1_rc3b.x |
xine / xine | 1_beta2 | 1_beta2.x |
xine / xine | 0.9.8 | 0.9.8.x |
xine / xine | 1_rc3a | 1_rc3a.x |
xine / xine-ui | 0.9.21 | 0.9.21.x |
xine / xine | 1_rc2 | 1_rc2.x |
xine / xine-lib | 1_rc3c | 1_rc3c.x |
xine / xine | 1_beta10 | 1_beta10.x |
xine / xine | 1_beta12 | 1_beta12.x |
xine / xine-ui | 0.9.23 | 0.9.23.x |
xine / xine | 1_beta11 | 1_beta11.x |
xine / xine | 1_beta7 | 1_beta7.x |
xine / xine | 1_beta8 | 1_beta8.x |
xine / xine | 0.9.13 | 0.9.13.x |
xine / xine | 1_rc1 | 1_rc1.x |
xine / xine-lib | 1_rc2 | 1_rc2.x |
xine / xine | 1_beta6 | 1_beta6.x |
xine / xine | 1_beta1 | 1_beta1.x |
xine / xine | 1_rc3 | 1_rc3.x |
xine / xine-lib | 1_rc3a | 1_rc3a.x |
xine / xine-ui | 0.9.22 | 0.9.22.x |
xine / xine | 1_beta5 | 1_beta5.x |