FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-2948

This CVE name corresponds to:

Entered Topic
2007-06-07 mplayer -- cddb stack overflow

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-2948
Phase Assigned(20070531)

Description

Multiple stack-based buffer overflows in stream/stream_cddb.c in MPlayer before 1.0rc1try3 allow remote attackers to execute arbitrary code via a CDDB entry with a long (1) album title or (2) category.

References

Source Reference
MLIST [MPlayer-announce] 20070605 MPlayer 1.0rc1try3 released
MISC http://secunia.com/secunia_research/2007-55/
CONFIRM http://svn.mplayerhq.hu/mplayer/trunk/stream/stream_cddb.c?r1=23287&r2=23470&diff_format=u
CONFIRM http://www.mplayerhq.hu/design7/news.html
DEBIAN DSA-1313
GENTOO GLSA-200707-07
MANDRIVA MDKSA-2007:143
SUSE SUSE-SR:2007:014
BID 24339
OSVDB 36991
VUPEN ADV-2007-2080
SECUNIA 24302
SECUNIA 25713
SECUNIA 25940
SECUNIA 26083
SECUNIA 26207
XF mplayer-cddb-bo(34749)