CVE-2006-1905
EPSS 14.3%
Description
Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote attackers to execute arbitrary code via format string specifiers in a long filename on an EXTINFO line in a playlist file.
How to fix CVE-2006-1905
To remediate CVE-2006-1905, upgrade the affected package to a fixed version below.
- Debian/xine-ui—upgrade to 0.99.4-1 or later
Is CVE-2006-1905 being exploited?
Moderate — EPSS is 14.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 0.99.4-1