Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

MPlayer AVIHeader.C Heap Based Buffer Overflow Vulnerability

MPlayer is prone to a heap-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input data.

Attackers can exploit this issue to execute arbitrary code with the privileges of the user running the application. Failed attacks will result in denial-of-service conditions.

MPlayer 1.0rc1 is vulnerable; other versions may also be affected.

NOTE: The vendor states that this issue is present only on operating systems with a 'calloc' implementation that is prone to an integer-overflow issue.







 

Privacy Statement
Copyright 2009, SecurityFocus