CVE-2004-1951
EPSS 8.1%
Description
xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options in an MRL link.
How to fix CVE-2004-1951
To remediate CVE-2004-1951, upgrade the affected package to a fixed version below.
- Debian/xine-ui—upgrade to 0.99.1 or later
Is CVE-2004-1951 being exploited?
Moderate — EPSS is 8.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 0.99.1