Lucene search

K
cveRedhatCVE-2008-3827
HistorySep 29, 2008 - 7:25 p.m.

CVE-2008-3827

2008-09-2919:25:59
CWE-189
redhat
web.nvd.nist.gov
42
cve-2008-3827
integer underflows
real demuxer
mplayer
denial of service
arbitrary code
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

High

EPSS

0.06

Percentile

93.5%

Multiple integer underflows in the Real demuxer (demux_real.c) in MPlayer 1.0_rc2 and earlier allow remote attackers to cause a denial of service (process termination) and possibly execute arbitrary code via a crafted video file that causes the stream_read function to read or write arbitrary memory.

Affected configurations

Nvd
Node
mplayermplayerRange1.0_rc2
OR
mplayermplayerMatch0.90
OR
mplayermplayerMatch0.90_pre
OR
mplayermplayerMatch0.90_rc
OR
mplayermplayerMatch0.90_rc4
OR
mplayermplayerMatch0.91
OR
mplayermplayerMatch0.92
OR
mplayermplayerMatch0.92.1
OR
mplayermplayerMatch0.92_cvs
OR
mplayermplayerMatch1.0_pre1
OR
mplayermplayerMatch1.0_pre2
OR
mplayermplayerMatch1.0_pre3
OR
mplayermplayerMatch1.0_pre3try2
OR
mplayermplayerMatch1.0_pre4
OR
mplayermplayerMatch1.0_pre5
OR
mplayermplayerMatch1.0_pre5try1
OR
mplayermplayerMatch1.0_pre5try2
OR
mplayermplayerMatch1.0_pre6
OR
mplayermplayerMatch1.0_pre7
OR
mplayermplayerMatch1.0_pre7try2
OR
mplayermplayerMatch1.0_rc1
VendorProductVersionCPE
mplayermplayer0.92+cvscpe:/a:mplayer:mplayer:0.92+cvs:::
mplayermplayer0.90+precpe:/a:mplayer:mplayer:0.90+pre:::
mplayermplayer1.0+pre5try1cpe:/a:mplayer:mplayer:1.0+pre5try1:::
mplayermplayer0.90cpe:/a:mplayer:mplayer:0.90:::
mplayermplayer0.90+rccpe:/a:mplayer:mplayer:0.90+rc:::
mplayermplayer0.90+rc4cpe:/a:mplayer:mplayer:0.90+rc4:::
mplayermplayer1.0+pre7cpe:/a:mplayer:mplayer:1.0+pre7:::
mplayermplayer1.0+pre5cpe:/a:mplayer:mplayer:1.0+pre5:::
mplayermplayer1.0+pre7try2cpe:/a:mplayer:mplayer:1.0+pre7try2:::
mplayermplayer1.0+pre1cpe:/a:mplayer:mplayer:1.0+pre1:::
Rows per page:
1-10 of 211

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

High

EPSS

0.06

Percentile

93.5%