New xine-lib packages are available for Slackware 10.0, 10.1, 10.2, 11.0, 12.0, and -current to fix security issues.

An overflow was found in the Speex decoder that could lead to a crash or
possible execution of arbitrary code. Xine-lib lt;= 1.1.12 was also found to be vulnerable to a stack-based buffer overflow in the NES demuxer (thanks to

More details about the first issue may be found in the Common Vulnerabilities and Exposures (CVE) database:

Here are the details from the Slackware 12.0 ChangeLog:
Recompiled, with --without-speex (we didn't ship the speex library in
Slackware anyway, but for reference this issue would be CVE-2008-1686),
and with --disable-nosefart (the recently reported as insecurely
demuxed NSF format). As before in -2, this package fixes the two
regressions mentioned in the release notes for xine-lib-1.1.12:
(* Security fix *)

Where to find the new packages:

Installation instructions:

Upgrade the package as root:
# upgradepkg xine-lib-


