CVE-2008-1686
Last modified
CVE-2008-1686 is a vulnerability of currently unknown severity. Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative offset, which is used to dereference a function pointer.. EPSS estimates a 6.14% chance of exploitation in the next 30 days.
Description
Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative offset, which is used to dereference a function pointer.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xine | Xine-Lib | <= 1.1.11.1 |
| Xine | Xine-Lib | 0.9.8 |
| Xine | Xine-Lib | 0.9.13 |
| Xine | Xine-Lib | 0.99 |
| Xine | Xine-Lib | 1.0 |
| Xine | Xine-Lib | 1.0.1 |
| Xine | Xine-Lib | 1.0.2 |
| Xine | Xine-Lib | 1.0.3a |
| Xine | Xine-Lib | 1.1.0 |
| Xine | Xine-Lib | 1.1.1 |
| Xine | Xine-Lib | 1.1.10 |
| Xine | Xine-Lib | 1.1.10.1 |
| Xine | Xine-Lib | 1.1.11 |
| Xiph | Speex | <= 1.1.12 |
| Xiph | Speex | 1.0.2 |
| Xiph | Speex | 1.0.3 |
| Xiph | Speex | 1.0.4 |
| Xiph | Speex | 1.0.5 |
| Xiph | Speex | 1.1.1 |
| Xiph | Speex | 1.1.2 |
| Xiph | Speex | 1.1.3 |
| Xiph | Speex | 1.1.4 |
| Xiph | Speex | 1.1.5 |
| Xiph | Speex | 1.1.6 |
| Xiph | Speex | 1.1.7 |
| Xiph | Speex | 1.1.8 |
| Xiph | Speex | 1.1.9 |
| Xiph | Speex | 1.1.10 |
| Xiph | Speex | 1.1.11 |
| Xiph | Speex | 1.1.11.1 |
| Xiph | Libfishsound | <= 0.9.0 |
| Xiph | Libfishsound | 0.5.41 |
| Xiph | Libfishsound | 0.5.42 |
| Xiph | Libfishsound | 0.6.0 |
| Xiph | Libfishsound | 0.6.1 |
| Xiph | Libfishsound | 0.6.2 |
| Xiph | Libfishsound | 0.6.3 |
| Xiph | Libfishsound | 0.7.0 |
| Xiph | Libfishsound | 0.8.0 |
| Xiph | Libfishsound | 0.8.1 |
References
- http://secunia.com/advisories/29672Vendor Advisory
- http://secunia.com/advisories/29727Vendor Advisory
- http://secunia.com/advisories/29835Vendor Advisory
- http://secunia.com/advisories/29845Vendor Advisory
- http://secunia.com/advisories/29854Vendor Advisory
- http://secunia.com/advisories/29866Vendor Advisory
- http://secunia.com/advisories/29878Vendor Advisory
- http://secunia.com/advisories/29880Vendor Advisory
- http://secunia.com/advisories/29881Vendor Advisory
- http://secunia.com/advisories/29882Vendor Advisory
- http://secunia.com/advisories/29898Vendor Advisory
- http://secunia.com/advisories/30104Vendor Advisory
- http://secunia.com/advisories/30117Vendor Advisory
- http://secunia.com/advisories/30119Vendor Advisory
- http://secunia.com/advisories/30353Vendor Advisory
- http://secunia.com/advisories/30358Vendor Advisory
- http://secunia.com/advisories/30581Vendor Advisory
- http://secunia.com/advisories/31393Vendor Advisory
- http://secunia.com/advisories/29672Vendor Advisory
- http://secunia.com/advisories/29727Vendor Advisory
- http://secunia.com/advisories/29835Vendor Advisory
- http://secunia.com/advisories/29845Vendor Advisory
- http://secunia.com/advisories/29854Vendor Advisory
- http://secunia.com/advisories/29866Vendor Advisory
- http://secunia.com/advisories/29878Vendor Advisory
- http://secunia.com/advisories/29880Vendor Advisory
- http://secunia.com/advisories/29881Vendor Advisory
- http://secunia.com/advisories/29882Vendor Advisory
- http://secunia.com/advisories/29898Vendor Advisory
- http://secunia.com/advisories/30104Vendor Advisory
- http://secunia.com/advisories/30117Vendor Advisory
- http://secunia.com/advisories/30119Vendor Advisory
- http://secunia.com/advisories/30353Vendor Advisory
- http://secunia.com/advisories/30358Vendor Advisory
- http://secunia.com/advisories/30581Vendor Advisory
- http://secunia.com/advisories/31393Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-1686?
How severe is CVE-2008-1686?
How do I fix CVE-2008-1686?
Are you affected by CVE-2008-1686?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
