Vulnerability Name: | CVE-2007-1246 (CCN-32747) | ||||||||||||||||||||
Assigned: | 2007-03-01 | ||||||||||||||||||||
Published: | 2007-03-01 | ||||||||||||||||||||
Updated: | 2018-10-16 | ||||||||||||||||||||
Summary: | The DMO_VideoDecoder_Open function in loader/dmo/DMO_VideoDecoder.c in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1387. Failed exploit attempts will likely result in a denial-of-service condition. | ||||||||||||||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||
CVSS v2 Severity: | 7.6 High (CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C) 5.6 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Tue Feb 27 2007 - 09:20:48 CST MPlayer: Buffer overflow Source: MITRE Type: CNA CVE-2007-1246 Source: FULLDISC Type: UNKNOWN 20070301 MPlayer DMO buffer overflow Source: CCN Type: SA24443 xine-lib Two Buffer Overflow Vulnerabilities Source: SECUNIA Type: Vendor Advisory 24443 Source: CCN Type: SA24444 MPlayer Two Buffer Overflow Vulnerabilities Source: SECUNIA Type: Vendor Advisory 24444 Source: SECUNIA Type: Vendor Advisory 24446 Source: SECUNIA Type: Vendor Advisory 24448 Source: SECUNIA Type: Vendor Advisory 24462 Source: SECUNIA Type: Vendor Advisory 24866 Source: SECUNIA Type: Vendor Advisory 24897 Source: SECUNIA Type: Vendor Advisory 24995 Source: SECUNIA Type: Vendor Advisory 25462 Source: SECUNIA Type: Vendor Advisory 29601 Source: GENTOO Type: UNKNOWN GLSA-200704-09 Source: GENTOO Type: UNKNOWN GLSA-200705-21 Source: SLACKWARE Type: UNKNOWN SSA:2007-109-02 Source: CONFIRM Type: Patch http://svn.mplayerhq.hu/mplayer/trunk/loader/dmo/DMO_VideoDecoder.c Source: MISC Type: UNKNOWN http://svn.mplayerhq.hu/mplayer/trunk/loader/dmo/DMO_VideoDecoder.c?r1=22019&r2=22204 Source: DEBIAN Type: UNKNOWN DSA-1536 Source: DEBIAN Type: DSA-1536 libxine -- several vulnerabilities Source: CCN Type: GLSA-200704-09 xine-lib: Heap-based buffer overflow Source: CCN Type: GLSA-200705-21 MPlayer: Two buffer overflows Source: MANDRIVA Type: UNKNOWN MDKSA-2007:055 Source: MANDRIVA Type: UNKNOWN MDKSA-2007:057 Source: CCN Type: MPlayer Web site MPlayer - The Movie Player Source: SUSE Type: UNKNOWN SUSE-SR:2007:007 Source: SUSE Type: UNKNOWN SUSE-SR:2007:005 Source: CCN Type: OSVDB ID: 33996 MPlayer DirectShow Loader biSize Overflow Source: BUGTRAQ Type: UNKNOWN 20070423 FLEA-2007-0013-1: xine-lib Source: BID Type: UNKNOWN 22771 Source: CCN Type: BID-22771 MPlayer DMO File Parsing Buffer Overflow Vulnerability Source: CCN Type: TLSA-2007-33 Buffer overflows Source: CCN Type: USN-433-1 Xine vulnerability Source: UBUNTU Type: UNKNOWN USN-433-1 Source: VUPEN Type: Vendor Advisory ADV-2007-0794 Source: XF Type: UNKNOWN mplayer-dmovideodecoder-bo(32747) Source: XF Type: UNKNOWN mplayer-dmovideodecoder-bo(32747) Source: SUSE Type: SUSE-SR:2007:005 SUSE Security Summary Report Source: SUSE Type: SUSE-SR:2007:007 SUSE Security Summary Report | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |