PT-2007-2781 · Mplayer Team · Mplayer
Kees Cook
·
Published
2007-03-13
·
Updated
2018-10-03
·
CVE-2007-1387
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:H/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MPlayer versions 1.0rc1 and earlier
Description
The issue is related to the DirectShow loader in MPlayer, which does not properly set the
biSize before using it in a memcpy function. This can lead to a buffer overflow, potentially allowing remote attackers to execute arbitrary code. The issue is user-assisted, meaning it requires some action from the user to be exploited.Recommendations
For MPlayer versions 1.0rc1 and earlier, consider updating to a newer version that addresses this issue, as the current version may allow for arbitrary code execution due to the buffer overflow vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mplayer