PT-2006-6803 · Mplayer+1 · Mplayer+1
Published
2006-11-30
·
Updated
2011-03-08
·
CVE-2006-6172
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
xine/xine-lib (affected versions not specified)
MPlayer versions prior to 1.0rc1
Description
The issue is related to a buffer overflow in the asmrp eval function, which is part of the RealMedia RTSP stream handler in the Real Media input plugin. This can be exploited by remote attackers to cause a denial of service and potentially execute arbitrary code. The exploitation is possible via a rulebook containing a large number of rulematches.
Recommendations
For xine/xine-lib, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For MPlayer versions prior to 1.0rc1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mplayer
Xine-Lib