|
|

CVE Reference: CVE-2007-1387 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2007-1387 |
|
|
Description: The DirectShow loader (loader/dshow/DS_VideoDecoder.c) in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1246. |
|
|
CVE Status: Candidate |
|
|
References: UBUNTU http://www.ubuntulinux.org/support/documentation/usn/usn-435-1 SAID Secunia Advisory: SA24462 Secunia Advisory: SA24444 Secunia Advisory: SA25462 Secunia Advisory: SA24443 Secunia Advisory: SA29601 MISC http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=414072;msg=12;filename=DS_VideoDecoder.c---SVN--22205.patch;att=1 MANDRIVA http://www.mandriva.com/security/advisories?name=MDKSA-2007:062 http://www.mandriva.com/security/advisories?name=MDKSA-2007:061 GENTOO http://security.gentoo.org/glsa/glsa-200705-21.xml DEBIAN http://www.debian.org/security/2008/dsa-1536 CONFIRM http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=414072 BID 22933 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |