Lucene search

K
osvGoogleOSV:DSA-2044-1
HistoryMay 11, 2010 - 12:00 a.m.

mplayer - arbitrary code execution

2010-05-1100:00:00
Google
osv.dev
8

0.095 Low

EPSS

Percentile

94.8%

tixxDZ (DZCORE labs) discovered a vulnerability in the mplayer movie
player. Missing data validation in mplayer’s real data transport (RDT)
implementation enable an integer underflow and consequently an unbounded
buffer operation. A maliciously crafted stream could thus enable an
attacker to execute arbitrary code.

No Common Vulnerabilities and Exposures project identifier is available for
this issue.

For the stable distribution (lenny), this problem has been fixed in version
1.0~rc2-17+lenny3.2.

We recommend that you upgrade your mplayer packages.

0.095 Low

EPSS

Percentile

94.8%