FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-0579

This CVE name corresponds to:

Entered Topic
2006-03-09 mplayer -- heap overflow in the ASF demuxer

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-0579
Phase Assigned(20060208)

Description

Multiple integer overflows in (1) the new_demux_packet function in demuxer.h and (2) the demux_asf_read_packet function in demux_asf.c in MPlayer 1.0pre7try2 and earlier allow remote attackers to execute arbitrary code via an ASF file with a large packet length value. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.

References

Source Reference
GENTOO GLSA-200603-03
MANDRIVA MDKSA-2006:048
VUPEN ADV-2006-0457
SECUNIA 18718
SECUNIA 19114
XF mplayer-asf-integer-overflow(24531)