LWN.net Logo

Advertisement

Front, Kernel, Security, Distributions, Development. See your byline here on LWN.net.

Advertise here

mplayer: multiple vulnerabilities

Package(s):mplayer CVE #(s):CVE-2008-0485 CVE-2008-0486 CVE-2008-0629 CVE-2008-0630
Created:February 13, 2008 Updated:August 7, 2008
Description:

From the Debian advisory:

Several buffer overflows have been discovered in the MPlayer movie player, which might lead to the execution of arbitrary code. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2008-0485: Felipe Manzano and Anibal Sacco discovered a buffer overflow in the demuxer for MOV files.

CVE-2008-0486: Reimar Doeffinger discovered a buffer overflow in the FLAC header parsing.

CVE-2008-0629: Adam Bozanich discovered a buffer overflow in the CDDB access code.

CVE-2008-0630: Adam Bozanich discovered a buffer overflow in URL parsing.

Alerts:
Ubuntu USN-635-1 2008-08-06
Debian DSA-1536-1 2008-03-31
Gentoo 200802-12 2008-02-26
Mandriva MDVSA-2008:045 2007-02-14
SuSE SUSE-SR:2008:006 2008-03-14
Gentoo 200803-16 2008-03-10
Mandriva MDVSA-2008:046-1 2007-02-20
Mandriva MDVSA-2008:046 2007-02-15
Fedora FEDORA-2008-1543 2008-02-13
Fedora FEDORA-2008-1581 2008-02-13
Debian DSA-1496-1 2008-02-12

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds