10
CVSSv2

CVE-2004-1187

Published: 10/01/2005 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote malicious users to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.

Vulnerable Product Search on Vulmon Subscribe to Product

mplayer mplayer 0.90_pre

mplayer mplayer 0.90_rc

mplayer mplayer 1.0_pre2

mplayer mplayer 1.0_pre3

xine xine-lib 0.9.8

xine xine-lib 0.99

xine xine-lib 1_beta3

xine xine-lib 1_beta4

xine xine-lib 1_rc1

xine xine-lib 1_rc2

xine xine-lib 1_rc6a

xine xine-lib 1_rc7

xine xine 1_beta11

xine xine 1_beta12

xine xine 1_beta8

xine xine 1_beta9

xine xine 1_rc0

xine xine 1_rc4

xine xine 1_rc5

mplayer mplayer 0.90

mplayer mplayer 0.92_cvs

mplayer mplayer 1.0_pre1

mplayer mplayer head_cvs

xine xine-lib 0.9.13

xine xine-lib 1_beta12

xine xine-lib 1_beta2

xine xine-lib 1_beta9

xine xine-lib 1_rc0

xine xine-lib 1_rc5

xine xine-lib 1_rc6

xine xine 1_beta1

xine xine 1_beta10

xine xine 1_beta6

xine xine 1_beta7

xine xine 1_rc3a

mplayer mplayer 0.92

mplayer mplayer 0.92.1

mplayer mplayer 1.0_pre5try1

mplayer mplayer 1.0_pre5try2

xine xine-lib 1_beta10

xine xine-lib 1_beta11

xine xine-lib 1_beta7

xine xine-lib 1_beta8

xine xine-lib 1_rc3c

xine xine-lib 1_rc4

xine xine 0.9.8

xine xine 1_alpha

xine xine 1_beta4

xine xine 1_beta5

xine xine 1_rc2

xine xine 1_rc3

xine xine 1_rc7

xine xine 1_rc8

xine xine 1_rc3b

mplayer mplayer 0.90_rc4

mplayer mplayer 0.91

mplayer mplayer 1.0_pre3try2

mplayer mplayer 1.0_pre4

mplayer mplayer 1.0_pre5

xine xine-lib 1_alpha

xine xine-lib 1_beta1

xine xine-lib 1_beta5

xine xine-lib 1_beta6

xine xine-lib 1_rc3

xine xine-lib 1_rc3a

xine xine-lib 1_rc3b

xine xine 0.9.13

xine xine 0.9.18

xine xine 1_beta2

xine xine 1_beta3

xine xine 1_rc0a

xine xine 1_rc1

xine xine 1_rc6

xine xine 1_rc6a

mandrakesoft mandrake linux 10.0

mandrakesoft mandrake linux 10.1