CVE-2007-1246
CVE-2007-1246
The DMO_VideoDecoder_Open function in loader/dmo/DMO_VideoDecoder.c in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1387.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/052738.htmlhttp://secunia.com/advisories/24443http://secunia.com/advisories/24444http://secunia.com/advisories/24446http://secunia.com/advisories/24448http://secunia.com/advisories/24462http://secunia.com/advisories/24866http://secunia.com/advisories/24897http://secunia.com/advisories/24995http://secunia.com/advisories/25462http://secunia.com/advisories/29601http://security.gentoo.org/glsa/glsa-200704-09.xml