PT-2006-6803 · Mplayer+1 · Mplayer+1

Published

2006-11-30

·

Updated

2011-03-08

·

CVE-2006-6172

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions xine/xine-lib (affected versions not specified) MPlayer versions prior to 1.0rc1
Description The issue is related to a buffer overflow in the asmrp eval function, which is part of the RealMedia RTSP stream handler in the Real Media input plugin. This can be exploited by remote attackers to cause a denial of service and potentially execute arbitrary code. The exploitation is possible via a rulebook containing a large number of rulematches.
Recommendations For xine/xine-lib, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For MPlayer versions prior to 1.0rc1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6172
DSA-1244-1

Affected Products

Mplayer
Xine-Lib