7.6

CVE-2007-4938

Exploit
Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values, and a certain wLongsPerEntry value.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mplayer ≫ Mplayer Version 1.0_rc1
   Apple ≫ macOS X
   Hp ≫ Hp-ux
   Hp ≫ Tru64
   Ibm ≫ Aix
   Ibm ≫ Os2
   Linux ≫ Linux Kernel
   Mandrakesoft ≫ Mandrake Linux Version 2007
   Mandrakesoft ≫ Mandrake Linux Version 2007 Edition x86_64
   Mandrakesoft ≫ Mandrake Linux Version 2007.1
   Mandrakesoft ≫ Mandrake Linux Version 2007.1 Edition x86_64
   Microsoft ≫ Windows 2000
   Microsoft ≫ Windows 2003 Server
   Microsoft ≫ Windows 98
   Microsoft ≫ Windows Me
   Microsoft ≫ Windows Nt Version 4.0
   Microsoft ≫ Windows Xp
   Santa Cruz Operation ≫ Sco Unix
   Sun ≫ Solaris
   Windriver ≫ Bsdos
Sgi ≫ Irix
   Apple ≫ macOS X
   Hp ≫ Hp-ux
   Hp ≫ Tru64
   Ibm ≫ Aix
   Ibm ≫ Os2
   Linux ≫ Linux Kernel
   Mandrakesoft ≫ Mandrake Linux Version 2007
   Mandrakesoft ≫ Mandrake Linux Version 2007 Edition x86_64
   Mandrakesoft ≫ Mandrake Linux Version 2007.1
   Mandrakesoft ≫ Mandrake Linux Version 2007.1 Edition x86_64
   Microsoft ≫ Windows 2000
   Microsoft ≫ Windows 2003 Server
   Microsoft ≫ Windows 98
   Microsoft ≫ Windows Me
   Microsoft ≫ Windows Nt Version 4.0
   Microsoft ≫ Windows Xp
   Santa Cruz Operation ≫ Sco Unix
   Sun ≫ Solaris
   Windriver ≫ Bsdos
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 16.05% 0.965
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.6 4.9 10
AV:N/AC:H/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://osvdb.org/45940
http://secunia.com/advisories/27016
Vendor Advisory
http://securityreason.com/securityalert/3144
http://www.mandriva.com/security/advisories?name=MDKSA-2007:192
http://www.securityfocus.com/archive/1/479222/100/0/threaded
http://www.securityfocus.com/bid/25648
Exploit
http://www.vulnhunt.com/advisories/CAL-20070912-1_Multiple_vendor_produce_handling_AVI_file_vulnerabilities.txt
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/36581