CVE Database
/

CVE-2007-1246

Back to search

CVE-2007-1246

Published: Mar 3, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

The DMO_VideoDecoder_Open function in loader/dmo/DMO_VideoDecoder.c in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1387.

VendorProductVersions

n/a

n/a

affected
n/a

References

20070301 MPlayer DMO buffer overflow
mailing-list
x_refsource_FULLDISC
SUSE-SR:2007:005
vendor-advisory
x_refsource_SUSE
MDKSA-2007:057
vendor-advisory
x_refsource_MANDRIVA
SUSE-SR:2007:007
vendor-advisory
x_refsource_SUSE
20070423 FLEA-2007-0013-1: xine-lib
mailing-list
x_refsource_BUGTRAQ
24995
third-party-advisory
x_refsource_SECUNIA
24866
third-party-advisory
x_refsource_SECUNIA
24462
third-party-advisory
x_refsource_SECUNIA
29601
third-party-advisory
x_refsource_SECUNIA
USN-433-1
vendor-advisory
x_refsource_UBUNTU
24448
third-party-advisory
x_refsource_SECUNIA
ADV-2007-0794
vdb-entry
x_refsource_VUPEN
24446
third-party-advisory
x_refsource_SECUNIA
mplayer-dmovideodecoder-bo(32747)
vdb-entry
x_refsource_XF
MDKSA-2007:055
vendor-advisory
x_refsource_MANDRIVA
25462
third-party-advisory
x_refsource_SECUNIA
DSA-1536
vendor-advisory
x_refsource_DEBIAN
GLSA-200704-09
vendor-advisory
x_refsource_GENTOO
24444
third-party-advisory
x_refsource_SECUNIA
24443
third-party-advisory
x_refsource_SECUNIA
GLSA-200705-21
vendor-advisory
x_refsource_GENTOO
SSA:2007-109-02
vendor-advisory
x_refsource_SLACKWARE
24897
third-party-advisory
x_refsource_SECUNIA
22771
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now