LWN.net Logo

mplayer: arbitrary code execution

Package(s):MPlayer CVE #(s):CVE-2008-5616
Created:January 12, 2009 Updated:April 29, 2009
Description:

From the Gentoo advisory:

Tobias Klein reported a stack-based buffer overflow in the demux_open_vqf() function in libmpdemux/demux_vqf.c when processing malformed TwinVQ files (CVE-2008-5616).

A remote attacker could entice a user to open a specially crafted STR, Real Media, or TwinVQ file to execute arbitrary code or cause a Denial of Service.

Alerts:
Debian DSA-1782-1 2009-04-29
Gentoo 200901-07:02 2009-01-12
Mandriva MDVSA-2009:014 2008-01-15
Mandriva MDVSA-2009:013 2008-01-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds