CVE-2008-0630 buffer overflow via crafted url

Bug #191410 reported by Laurent Bigonville
254
Affects Status Importance Assigned to Milestone
mplayer (Debian)
Fix Released
Unknown
mplayer (Ubuntu)
New
High
Unassigned

Bug Description

Binary package hint: mplayer

Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for mplayer.

CVE-2008-0630[0]:
| Buffer overflow in url.c in MPlayer 1.0rc2 and SVN before r25823
| allows remote attackers to execute arbitrary code via a crafted URL
| that prevents the IPv6 parsing code from setting a pointer to NULL,
| which causes the buffer to be reused by the unescape code.

You can find a patch for this on:
http://svn.mplayerhq.hu/mplayer/trunk/stream/url.c?r1=25820&r2=25823

CVE References

Changed in mplayer:
importance: Undecided → High
description: updated
Changed in mplayer:
status: Unknown → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.