Description: Some vulnerabilities have been reported in xine-lib, which potentially can be exploited by malicious people to compromise a user's system.
1) A vulnerability is caused due to a boundary error within the "real_parse_sdp()" function in src/input/libreal/real.c. This can be exploited to cause a buffer overflow by e.g. tricking a user into connecting to a malicious server.
2) A buffer overflow exists in the libmms library. For more information: SA20749
Successful exploitation may allow the execution of arbitrary code.
The vulnerabilities are reported in versions prior to 1.1.3.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.