6.8
CVSSv2

CVE-2008-0630

Published: 06/02/2008 Updated: 05/09/2008
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in url.c in MPlayer 1.0rc2 and SVN before r25823 allows remote malicious users to execute arbitrary code via a crafted URL that prevents the IPv6 parsing code from setting a pointer to NULL, which causes the buffer to be reused by the unescape code.

Vulnerable Product Search on Vulmon Subscribe to Product

mplayer mplayer 1.02rc2

Vendor Advisories

Debian Bug report logs - #464533 mplayer: CVE-2008-0629 buffer overflow via crafted cddb title Package: mplayer; Maintainer for mplayer is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for mplayer is src:mplayer (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Thu, 7 ...
Debian Bug report logs - #464060 CVE-2008-0485/-0486: Vulnerabilities in mplayer Package: mplayer; Maintainer for mplayer is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for mplayer is src:mplayer (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Mon, 4 Feb 2008 2 ...
Debian Bug report logs - #464532 mplayer: CVE-2008-0630 buffer overflow via crafted url Package: mplayer; Maintainer for mplayer is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for mplayer is src:mplayer (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Thu, 7 Feb 20 ...