5
CVSSv2

CVE-2008-4610

Published: 20/10/2008 Updated: 20/03/2009
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 510
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

MPlayer allows remote malicious users to cause a denial of service (application crash) via (1) a malformed AAC file, as demonstrated by lol-vlc.aac; or (2) a malformed Ogg Media (OGM) file, as demonstrated by lol-ffplay.ogm, different vectors than CVE-2007-6718.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mplayer mplayer 1.0_pre5

mplayer mplayer 1.0_pre5try1

mplayer mplayer 0.91

mplayer mplayer 0.90_rc4

mplayer mplayer 1.0_pre3

mplayer mplayer 1.0_pre3try2

mplayer mplayer 1.0_pre4

mplayer mplayer 0.92_cvs

mplayer mplayer 0.92

mplayer mplayer 1.0_pre1

mplayer mplayer 1.0_pre2

mplayer mplayer 1.0_pre7

mplayer mplayer 1.0_pre7try2

mplayer mplayer 0.90

mplayer mplayer

mplayer mplayer 0.92.1

mplayer mplayer 1.0_pre5try2

mplayer mplayer 1.0_pre6

mplayer mplayer 0.90_rc

mplayer mplayer 0.90_pre

Vendor Advisories

It was discovered that FFmpeg did not correctly handle certain malformed Ogg Media (OGM) files If a user were tricked into opening a crafted Ogg Media file, an attacker could cause the application using FFmpeg to crash, leading to a denial of service (CVE-2008-4610) ...

Exploits

source: wwwsecurityfocuscom/bid/34136/info MPlayer is prone to multiple denial-of-service vulnerabilities when handling malformed media files Successfully exploiting this issue allows remote attackers to deny service to legitimate users githubcom/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/32856aac ...
source: wwwsecurityfocuscom/bid/34136/info MPlayer is prone to multiple denial-of-service vulnerabilities when handling malformed media files Successfully exploiting this issue allows remote attackers to deny service to legitimate users githubcom/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/32857ogm ...