9.3
CVSSv2

CVE-2007-2948

Published: 07/06/2007 Updated: 29/07/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple stack-based buffer overflows in stream/stream_cddb.c in MPlayer prior to 1.0rc1try3 allow remote malicious users to execute arbitrary code via a CDDB entry with a long (1) album title or (2) category.

Vulnerable Product Search on Vulmon Subscribe to Product

mplayer mplayer 1.0_rc1

Vendor Advisories

Stefan Cornelius and Reimar Doeffinger discovered that the MPlayer movie player performs insufficient boundary checks when accessing CDDB data, which might lead to the execution of arbitrary code The oldstable distribution (sarge) doesn't include MPlayer packages For the stable distribution (etch) this problem has been fixed in version 10~rc1-12 ...