PT-2006-6803 · Mplayer+1 · Mplayer+1

Publicado

2006-11-30

·

Atualizado

2011-03-08

·

CVE-2006-6172

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions xine/xine-lib (affected versions not specified) MPlayer versions prior to 1.0rc1
Description The issue is related to a buffer overflow in the asmrp eval function, which is part of the RealMedia RTSP stream handler in the Real Media input plugin. This can be exploited by remote attackers to cause a denial of service and potentially execute arbitrary code. The exploitation is possible via a rulebook containing a large number of rulematches.
Recommendations For xine/xine-lib, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For MPlayer versions prior to 1.0rc1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6172
DSA-1244-1

Produtos afetados

Mplayer
Xine-Lib