Description: Some vulnerabilities have been reported in MPlayer, which can potentially be exploited by malicious people to compromise a user's system.
The vulnerabilities are caused due to boundary errors in the "DMO_VideoDecoder_Open()" function in loader/dmo/DMO_VideoDecoder.c and in the "DS_VideoDecoder_Open()" function in loader/dshow/DS_VideoDecoder.c. These can be exploited to cause heap-based buffer overflows and may allow execution of arbitrary code via a specially crafted media file.
The vulnerabilities are reported in version 1.0rc1. Other versions may also be affected.
Solution: The vulnerabilities are fixed in the SVN repository.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.