oss-sec mailing list archives

Re: CVE id request: xine-lib insufficient boundary check in speex decoder


From: "Steven M. Christey" <coley () linus mitre org>
Date: Tue, 15 Apr 2008 20:24:52 -0400 (EDT)


On Wed, 16 Apr 2008, Nico Golde wrote:

Hi,
can I get a CVE id for:
http://sourceforge.net/project/shownotes.php?release_id=592185&group_id=9655
or could you add xine-lib to CVE-2008-1686?

The speex issue also seems to affect xine-lib.


With shared codebases, we use the same CVE.  I've updated it to mention
xine-lib.

- Steve


Current thread: