{ "schema_version": "1.4.0", "id": "GHSA-65qq-9m6q-q3fq", "modified": "2025-04-03T04:18:21Z", "published": "2022-05-01T02:13:17Z", "aliases": [ "CVE-2005-2967" ], "details": "Format string vulnerability in input_cdda.c in xine-lib 1-beta through 1-beta 3, 1-rc, 1.0 through 1.0.2, and 1.1.1 allows remote servers to execute arbitrary code via format string specifiers in metadata in CDDB server responses when the victim plays a CD.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2005-2967" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/22545" }, { "type": "WEB", "url": "http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0196.html" }, { "type": "WEB", "url": "http://secunia.com/advisories/17097" }, { "type": "WEB", "url": "http://secunia.com/advisories/17099" }, { "type": "WEB", "url": "http://secunia.com/advisories/17111" }, { "type": "WEB", "url": "http://secunia.com/advisories/17132" }, { "type": "WEB", "url": "http://secunia.com/advisories/17162" }, { "type": "WEB", "url": "http://secunia.com/advisories/17179" }, { "type": "WEB", "url": "http://secunia.com/advisories/17282" }, { "type": "WEB", "url": "http://slackware.com/security/viewer.php?l=slackware-security&y=2005&m=slackware-security.415454" }, { "type": "WEB", "url": "http://www.debian.org/security/2005/dsa-863" }, { "type": "WEB", "url": "http://www.gentoo.org/security/en/glsa/glsa-200510-08.xml" }, { "type": "WEB", "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2005:180" }, { "type": "WEB", "url": "http://www.novell.com/linux/security/advisories/2005_24_sr.html" }, { "type": "WEB", "url": "http://www.osvdb.org/19892" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/15044" }, { "type": "WEB", "url": "http://www.ubuntu.com/usn/usn-196-1" }, { "type": "WEB", "url": "http://xinehq.de/index.php/security/XSA-2005-1" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2005-10-14T10:02:00Z" } }