CVE-2008-1110

xine-lib < 1.1.10 - Buffer Overflow in ASF Demuxer

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-1110. PoCs published by Federico L. Bossi Bonin.

AI-analyzed exploit summary This Perl script is a proof-of-concept exploit for CVE-2008-1110, targeting a buffer overflow vulnerability in Libxine <= 1.14. It crafts a malicious MPEG file to trigger a segmentation fault, demonstrating the potential for arbitrary code execution.

Description

Buffer overflow in demuxers/demux_asf.c (aka the ASF demuxer) in the xineplug_dmx_asf.so plugin in xine-lib before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted ASF header. NOTE: this issue leads to a crash when an attack uses the CVE-2006-1664 exploit code, but it is different from CVE-2006-1664.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Federico L. Bossi Bonin · perldoslinux
https://www.exploit-db.com/exploits/1641

This Perl script is a proof-of-concept exploit for CVE-2008-1110, targeting a buffer overflow vulnerability in Libxine <= 1.14. It crafts a malicious MPEG file to trigger a segmentation fault, demonstrating the potential for arbitrary code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Libxine <= 1.14
No auth needed
Prerequisites: A vulnerable version of Libxine installed on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (12)

Core 12
Core References
Various Sources x_refsource_confirm
http://xinehq.de/index.php/security
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41019
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31393
Patch x_refsource_confirm
http://xinehq.de/index.php/news
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200802-12.xml
Issue Tracking x_refsource_confirm
http://bugs.gentoo.org/show_bug.cgi?id=208100
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2008:178
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29141
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/1641
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-635-1

Scores

EPSS 0.1037
EPSS Percentile 95.1%

Details

CWE
CWE-119
Status published
Products (2)
xine/xine-lib < 1.1.9
xine/xine-plugin < 1.1.9
Published Feb 29, 2008
Tracked Since Feb 18, 2026