CVE-2006-2230 describes multiple format string vulnerabilities in xine 0.99.4, specifically within the xiTK component (xitk/main.c). Attackers could exploit these flaws by providing specially crafted MP3 filenames containing format string specifiers on the command line, potentially leading to a denial of service. The vulnerability has a CVSS score of 5.0, indicating a medium severity, with a network attack vector and low attack complexity, resulting in a potential partial availability impact. While there is no evidence of active exploitation, an exploit for "Xine 0.99.x - Filename Handling Remote Format String" is available on ExploitDB, though it's important to note the original CVE description suggests it might not be a vulnerability if limited to user-assisted, local command-line arguments of non-setuid programs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.99.4CPE matchmatch criteria | cpe:2.3:a:xine:xine:0.99.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.