Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-3827
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-3827

Description:
Multiple integer underflows in the Real demuxer (demux_real.c) in MPlayer 1.0_rc2 and earlier allow remote attackers to cause a denial of service (process termination) and possibly execute arbitrary code via a crafted video file that causes the stream_read function to read or write arbitrary memory.

CVE Status:
Candidate

References:

ST
  1020952

SREASON
  http://securityreason.com/securityalert/4326

SAID
  Secunia Advisory: SA32153
  Secunia Advisory: SA32045

MISC
  http://www.ocert.org/advisories/ocert-2008-013.html

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDVSA-2008:219

DEBIAN
  http://www.debian.org/security/2008/dsa-1644

CONFIRM
  http://svn.mplayerhq.hu/mplayer/trunk/libmpdemux/demux_real.c?r1=27314&r2=27675

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/496806/100/0/threaded

BID
  31473


Return to the previous page.