Mandriva Linux Security Advisory – The DMO_VideoDecoder_Open function in dmo/DMO_VideoDecoder.c in xine-lib does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/54972/MDKSA-2007-057.txt
Source: https://packetstormsecurity.com/files/54972/Mandriva-Linux-Security-Advisory-2007.057.html

