Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2004-1188

Опубликовано: 10 янв. 2005
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 10

Описание

The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values, a different vulnerability than CVE-2004-1187.

РелизСтатусПримечание
dapper

released

1.1.1+ubuntu1-2
devel

DNE

edgy

released

1.1.1+ubuntu1-2
feisty

released

1.1.1+ubuntu1-2
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

1.1.1+ubuntu2-7.7
devel

released

1.1.4-2ubuntu3
edgy

released

1.1.2+repacked1-0ubuntu3.4
feisty

released

1.1.4-2ubuntu3
upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 65%
0.00495
Низкий

10 Critical

CVSS2

Связанные уязвимости

nvd
больше 20 лет назад

The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values, a different vulnerability than CVE-2004-1187.

debian
больше 20 лет назад

The pnm_get_chunk function in xine 0.99.2 and earlier, and other packa ...

github
больше 3 лет назад

The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values, a different vulnerability than CVE-2004-1187.

EPSS

Процентиль: 65%
0.00495
Низкий

10 Critical

CVSS2