CVE-2008-0225 describes a heap-based buffer overflow in the rmff_dump_cont function within xine-lib versions 1.1.9 and earlier. This vulnerability allows remote attackers to execute arbitrary code by sending a specially crafted SDP Abstract attribute during an RTSP session. With a CVSS score of 6.4, it is considered medium severity, requiring no authentication and having low attack complexity, potentially leading to partial confidentiality and integrity impacts. While there is no evidence of active exploitation in the wild, a proof-of-concept exploit is publicly available on ExploitDB, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.1.9CPE matchmatch criteria | cpe:2.3:a:xine:xine-lib:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.