10

CVE-2004-0386

Exploit
Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mplayer ≫ Mplayer Version 0.90
Mplayer ≫ Mplayer Version 0.90_pre
Mplayer ≫ Mplayer Version 0.90_rc
Mplayer ≫ Mplayer Version 0.91
Mplayer ≫ Mplayer Version 1.0_pre1
Mplayer ≫ Mplayer Version 1.0_pre2
Mplayer ≫ Mplayer Version 1.0_pre3
Gentoo ≫ Linux Version 0.5
Gentoo ≫ Linux Version 0.7
Gentoo ≫ Linux Version 1.1a
Gentoo ≫ Linux Version 1.2
Gentoo ≫ Linux Version 1.4
Gentoo ≫ Linux Version 1.4 Update rc1
Gentoo ≫ Linux Version 1.4 Update rc2
Gentoo ≫ Linux Version 1.4 Update rc3
Mandrakesoft ≫ Mandrake Linux Version 9.2
Mandrakesoft ≫ Mandrake Linux Version 10.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 26.98% 0.978
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.mplayerhq.hu/homepage/design6/news.html
http://marc.info/?l=bugtraq&m=108067020624076&w=2
http://secunia.com/advisories/11259
Patch
Vendor Advisory
http://security.gentoo.org/glsa/glsa-200403-13.xml
Patch
Vendor Advisory
http://www.kb.cert.org/vuls/id/723910
Patch
Third Party Advisory
US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2004:026
http://www.securityfocus.com/archive/1/359025
Patch
Vendor Advisory
http://www.securityfocus.com/bid/10008
Patch
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/15675