FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-6172

This CVE name corresponds to:

Entered Topic
2007-01-08 mplayer -- buffer overflow in the code for RealMedia RTSP streams.
2006-12-07 libxine -- multiple buffer overflow vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-6172
Phase Assigned(20061130)

Description

Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp.c) for Real Media input plugin, as used in (1) xine/xine-lib, (2) MPlayer 1.0rc1 and earlier, and possibly others, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a rulebook with a large number of rulematches.

References

Source Reference
MISC https://sourceforge.net/tracker/index.php?func=detail&aid=1603458&group_id=9655&atid=109655
MISC http://www.mplayerhq.hu/MPlayer/patches/asmrules_fix_20061231.diff
CONFIRM http://sourceforge.net/project/shownotes.php?release_id=468432
CONFIRM http://www.mplayerhq.hu/design7/news.html#vuln14
DEBIAN DSA-1244
GENTOO GLSA-200612-02
GENTOO GLSA-200702-11
MANDRIVA MDKSA-2006:224
MANDRIVA MDKSA-2007:112
SLACKWARE SSA:2006-357-05
SUSE SUSE-SR:2006:028
UBUNTU USN-392-1
BID 21435
VUPEN ADV-2006-4824
SECUNIA 23218
SECUNIA 23242
SECUNIA 23249
SECUNIA 23301
SECUNIA 23335
SECUNIA 23512
SECUNIA 23567
SECUNIA 24336
SECUNIA 24339
SECUNIA 25555