Summary
The remote host is missing an update as announced
via advisory SSA:2008-111-01.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=SSA:2008-111-01
Insight
New xine-lib packages are available for Slackware 10.0, 10.1, 10.2, 11.0, 12.0, and -current to fix security issues.
An overflow was found in the Speex decoder that could lead to a crash or possible execution of arbitrary code.
Xine-lib <= 1.1.12 was also found to be vulnerable to a stack-based buffer overflow in the NES demuxer (thanks to milw0rm.com).
More details about the first issue may be found in the Common Vulnerabilities and Exposures (CVE) database:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1686
Severity
Classification
-
CVE CVE-2008-1686 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities