CVE-2004-1951
xine 1.x alpha-1.0rc3a and xine-ui 0.9.21-0.9.23 - Arbitrary File Write via MRL Link Options
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1951. PoCs published by anonymous.
AI-analyzed exploit summary The writeup describes a file overwrite vulnerability in xine media player and library due to improper handling of configuration parameters, allowing arbitrary file writes on Sun-based systems or those using specific MPEG decoder cards.
Description
xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options in an MRL link.
Exploits (1)
The writeup describes a file overwrite vulnerability in xine media player and library due to improper handling of configuration parameters, allowing arbitrary file writes on Sun-based systems or those using specific MPEG decoder cards.