CVE Database
/

CVE-2007-1387

Back to search

CVE-2007-1387

Published: Mar 13, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

The DirectShow loader (loader/dshow/DS_VideoDecoder.c) in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1246.

VendorProductVersions

n/a

n/a

affected
n/a

References

24462
third-party-advisory
x_refsource_SECUNIA
22933
vdb-entry
x_refsource_BID
MDKSA-2007:061
vendor-advisory
x_refsource_MANDRIVA
29601
third-party-advisory
x_refsource_SECUNIA
USN-435-1
vendor-advisory
x_refsource_UBUNTU
MDKSA-2007:062
vendor-advisory
x_refsource_MANDRIVA
25462
third-party-advisory
x_refsource_SECUNIA
DSA-1536
vendor-advisory
x_refsource_DEBIAN
24444
third-party-advisory
x_refsource_SECUNIA
24443
third-party-advisory
x_refsource_SECUNIA
GLSA-200705-21
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2007-1387 - Security Vulnerability | QwikSec