Vulnerability Name:

CVE-2007-2948 (CCN-34749)

Assigned:2007-06-06
Published:2007-06-06
Updated:2017-07-29
Summary:Multiple stack-based buffer overflows in stream/stream_cddb.c in MPlayer before 1.0rc1try3 allow remote attackers to execute arbitrary code via a CDDB entry with a long (1) album title or (2) category.
CVSS v3 Severity:5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
5.1 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2007-2948

Source: CCN
Type: DSA 1313-1
New MPlayer packages fix arbitrary code execution

Source: MLIST
Type: Patch
[MPlayer-announce] 20070605 MPlayer 1.0rc1try3 released

Source: OSVDB
Type: UNKNOWN
36991

Source: CCN
Type: SA24302
MPlayer CDDB Parsing Buffer Overflows

Source: SECUNIA
Type: Patch, Vendor Advisory
24302

Source: SECUNIA
Type: UNKNOWN
25713

Source: SECUNIA
Type: UNKNOWN
25940

Source: SECUNIA
Type: UNKNOWN
26083

Source: SECUNIA
Type: UNKNOWN
26207

Source: MISC
Type: UNKNOWN
http://secunia.com/secunia_research/2007-55/

Source: CCN
Type: Secunia Research 06/06/2007
MPlayer CDDB Parsing Buffer Overflow

Source: GENTOO
Type: UNKNOWN
GLSA-200707-07

Source: CCN
Type: MPlayer ViewVC Web site
Diff of /trunk/stream/stream_cddb.c

Source: CONFIRM
Type: UNKNOWN
http://svn.mplayerhq.hu/mplayer/trunk/stream/stream_cddb.c?r1=23287&r2=23470&diff_format=u

Source: DEBIAN
Type: UNKNOWN
DSA-1313

Source: DEBIAN
Type: DSA-1313
mplayer -- buffer overflow

Source: CCN
Type: GLSA-200707-07
MPlayer: Multiple buffer overflows

Source: MANDRIVA
Type: UNKNOWN
MDKSA-2007:143

Source: CONFIRM
Type: UNKNOWN
http://www.mplayerhq.hu/design7/news.html

Source: SUSE
Type: UNKNOWN
SUSE-SR:2007:014

Source: CCN
Type: OSVDB ID: 36991
MPlayer stream/stream_cddb.c CDDB Parsing Overflow

Source: BID
Type: UNKNOWN
24339

Source: CCN
Type: BID-24339
MPlayer Multiple CDDB Parsing Buffer Overflow Vulnerabilities

Source: VUPEN
Type: UNKNOWN
ADV-2007-2080

Source: XF
Type: UNKNOWN
mplayer-cddb-bo(34749)

Source: XF
Type: UNKNOWN
mplayer-cddb-bo(34749)

Source: SUSE
Type: SUSE-SR:2007:014
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mplayer:mplayer:1.0_rc1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:mplayer:mplayer:1.0_rc1:*:*:*:*:*:*:*
  • AND
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007.1:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007.1::x86-64:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20072948
    V
    CVE-2007-2948
    2015-11-16
    oval:org.mitre.oval:def:20414
    P
    DSA-1313-1 mplayer
    2014-06-23
    oval:org.debian:def:1313
    V
    buffer overflow
    2007-06-19
    BACK
    mplayer mplayer 1.0_rc1
    mplayer mplayer 1.0_rc1
    gentoo linux *
    mandrakesoft mandrake linux corporate server 3.0
    mandrakesoft mandrake linux 2007
    mandrakesoft mandrake linux 2007
    mandrakesoft mandrake linux corporate server 3.0
    mandrakesoft mandrake linux 2007.1
    debian debian linux 4.0
    mandrakesoft mandrake linux 2007.1