PT-2008-6671 · Mplayer Team · Mplayer
Tobias Klein
·
Publicado
2008-12-17
·
Atualizado
2018-10-11
·
CVE-2008-5616
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MPlayer version 1.0 rc2 before r28150
Description
The issue is a stack-based buffer overflow in the demux open vqf function, located in libmpdemux/demux vqf.c. This allows remote attackers to execute arbitrary code via a malformed TwinVQ file.
Recommendations
For MPlayer version 1.0 rc2 before r28150, update to a version after r28150 to resolve the issue. As a temporary workaround, consider avoiding the use of the demux open vqf function until a patch is available. Restrict access to malformed TwinVQ files to minimize the risk of exploitation.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mplayer