10

CVE-2004-1188

The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values, a different vulnerability than CVE-2004-1187.

Data is provided by the National Vulnerability Database (NVD)
MplayerMplayer Version0.90
MplayerMplayer Version0.90_pre
MplayerMplayer Version0.90_rc
MplayerMplayer Version0.90_rc4
MplayerMplayer Version0.91
MplayerMplayer Version0.92
MplayerMplayer Version0.92.1
MplayerMplayer Version0.92_cvs
MplayerMplayer Version1.0_pre1
MplayerMplayer Version1.0_pre2
MplayerMplayer Version1.0_pre3
MplayerMplayer Version1.0_pre3try2
MplayerMplayer Version1.0_pre4
MplayerMplayer Version1.0_pre5
MplayerMplayer Version1.0_pre5try1
MplayerMplayer Version1.0_pre5try2
MplayerMplayer Versionhead_cvs
XineXine Version0.9.8
XineXine Version0.9.13
XineXine Version0.9.18
XineXine Version1_alpha
XineXine Version1_beta1
XineXine Version1_beta2
XineXine Version1_beta3
XineXine Version1_beta4
XineXine Version1_beta5
XineXine Version1_beta6
XineXine Version1_beta7
XineXine Version1_beta8
XineXine Version1_beta9
XineXine Version1_beta10
XineXine Version1_beta11
XineXine Version1_beta12
XineXine Version1_rc0
XineXine Version1_rc0a
XineXine Version1_rc1
XineXine Version1_rc2
XineXine Version1_rc3
XineXine Version1_rc3a
XineXine Version1_rc3b
XineXine Version1_rc4
XineXine Version1_rc5
XineXine Version1_rc6
XineXine Version1_rc6a
XineXine Version1_rc7
XineXine Version1_rc8
XineXine-lib Version0.9.8
XineXine-lib Version0.9.13
XineXine-lib Version0.99
XineXine-lib Version1_alpha
XineXine-lib Version1_beta1
XineXine-lib Version1_beta2
XineXine-lib Version1_beta3
XineXine-lib Version1_beta4
XineXine-lib Version1_beta5
XineXine-lib Version1_beta6
XineXine-lib Version1_beta7
XineXine-lib Version1_beta8
XineXine-lib Version1_beta9
XineXine-lib Version1_beta10
XineXine-lib Version1_beta11
XineXine-lib Version1_beta12
XineXine-lib Version1_rc0
XineXine-lib Version1_rc1
XineXine-lib Version1_rc2
XineXine-lib Version1_rc3
XineXine-lib Version1_rc3a
XineXine-lib Version1_rc3b
XineXine-lib Version1_rc3c
XineXine-lib Version1_rc4
XineXine-lib Version1_rc5
XineXine-lib Version1_rc6
XineXine-lib Version1_rc6a
XineXine-lib Version1_rc7
MandrakesoftMandrake Linux Version10.0
MandrakesoftMandrake Linux Version10.0 Editionamd64
MandrakesoftMandrake Linux Version10.1
MandrakesoftMandrake Linux Version10.1 Editionx86_64
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.5% 0.629
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C