7.5
CVSSv2

CVE-2006-6172

Published: 30/11/2006 Updated: 08/03/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp.c) for Real Media input plugin, as used in (1) xine/xine-lib, (2) MPlayer 1.0rc1 and previous versions, and possibly others, allows remote malicious users to cause a denial of service and possibly execute arbitrary code via a rulebook with a large number of rulematches.

Vulnerable Product Search on Vulmon Subscribe to Product

xine real media input plugin

mplayer mplayer

Vendor Advisories

A buffer overflow was discovered in the Real Media input plugin in xine-lib If a user were tricked into loading a specially crafted stream from a malicious server, the attacker could execute arbitrary code with the user’s privileges ...
Debian Bug report logs - #401740 CVE-2006-6172: xine-lib libreal Buffer Overflow Vulnerabilities Package: libxine1; Maintainer for libxine1 is (unknown); Reported by: Stefan Fritsch <sf@sfritschde> Date: Tue, 5 Dec 2006 17:03:18 UTC Severity: grave Tags: security Found in version xine-lib/112+dfsg-1 Fixed in version x ...
It was discovered that the Xine multimedia library performs insufficient sanitising of Real streams, which might lead to the execution of arbitrary code through a buffer overflow For the stable distribution (sarge) this problem has been fixed in version 101-1sarge5 For the upcoming stable distribution (etch) this problem has been fixed in versi ...