9.3
CVSSv2

CVE-2008-0485

Published: 05/02/2008 Updated: 15/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and previous versions might allow remote malicious users to execute arbitrary code via a QuickTime MOV file with a crafted stsc atom tag.

Vulnerable Product Search on Vulmon Subscribe to Product

mplayer mplayer

Vendor Advisories

Debian Bug report logs - #464533 mplayer: CVE-2008-0629 buffer overflow via crafted cddb title Package: mplayer; Maintainer for mplayer is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for mplayer is src:mplayer (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Thu, 7 ...
Debian Bug report logs - #464060 CVE-2008-0485/-0486: Vulnerabilities in mplayer Package: mplayer; Maintainer for mplayer is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for mplayer is src:mplayer (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Mon, 4 Feb 2008 2 ...
Debian Bug report logs - #464532 mplayer: CVE-2008-0630 buffer overflow via crafted url Package: mplayer; Maintainer for mplayer is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for mplayer is src:mplayer (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Thu, 7 Feb 20 ...

Exploits

source: wwwsecurityfocuscom/bid/27499/info MPlayer is prone to a remote code-execution vulnerability because it fails to sanitize certain 'MOV' file tags before using them to index heap memory An attacker can exploit this issue to execute arbitrary code, which can result in the complete compromise of the computer Failed exploit attempt ...