Back to search
CVE-2007-1246
Published: Mar 3, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
The DMO_VideoDecoder_Open function in loader/dmo/DMO_VideoDecoder.c in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1387.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://svn.mplayerhq.hu/mplayer/trunk/loader/dmo/DMO_VideoDecoder.c
x_refsource_CONFIRM
20070301 MPlayer DMO buffer overflow
mailing-list
x_refsource_FULLDISC
SUSE-SR:2007:005
vendor-advisory
x_refsource_SUSE
MDKSA-2007:057
vendor-advisory
x_refsource_MANDRIVA
SUSE-SR:2007:007
vendor-advisory
x_refsource_SUSE
20070423 FLEA-2007-0013-1: xine-lib
mailing-list
x_refsource_BUGTRAQ
24995
third-party-advisory
x_refsource_SECUNIA
24866
third-party-advisory
x_refsource_SECUNIA
24462
third-party-advisory
x_refsource_SECUNIA
29601
third-party-advisory
x_refsource_SECUNIA
USN-433-1
vendor-advisory
x_refsource_UBUNTU
24448
third-party-advisory
x_refsource_SECUNIA
ADV-2007-0794
vdb-entry
x_refsource_VUPEN
24446
third-party-advisory
x_refsource_SECUNIA
mplayer-dmovideodecoder-bo(32747)
vdb-entry
x_refsource_XF
MDKSA-2007:055
vendor-advisory
x_refsource_MANDRIVA
25462
third-party-advisory
x_refsource_SECUNIA
DSA-1536
vendor-advisory
x_refsource_DEBIAN
GLSA-200704-09
vendor-advisory
x_refsource_GENTOO
24444
third-party-advisory
x_refsource_SECUNIA
24443
third-party-advisory
x_refsource_SECUNIA
GLSA-200705-21
vendor-advisory
x_refsource_GENTOO
SSA:2007-109-02
vendor-advisory
x_refsource_SLACKWARE
24897
third-party-advisory
x_refsource_SECUNIA
22771
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now