Mandriva Linux Security Advisory – A format string vulnerability in the errors_create_window function in errors.c in xine-ui allows attackers to execute arbitrary code via unknown vectors. XINE 0.99.4 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a certain M3U file that contains a long #EXTINF line and contains format string specifiers in an invalid udp:// URI, possibly a variant of CVE-2007-0017.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/58453/MDKSA-2007-154.txt
Source: https://packetstormsecurity.com/files/58453/Mandriva-Linux-Security-Advisory-2007.154.html

