CVE-2008-5238
Integer overflow in the real_parse_mdpr function in demux_real.c in xine-lib 1.1.12, and other versions before 1.1.15, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted stream_name_size field.
Date published : 2008-11-25
http://www.securityfocus.com/bid/30797
http://www.securityfocus.com/archive/1/495674/100/0/threaded