Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2007-1246

Опубликовано: 03 мар. 2007
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.6

Описание

The DMO_VideoDecoder_Open function in loader/dmo/DMO_VideoDecoder.c in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1387.

РелизСтатусПримечание
dapper

released

2:0.99+1.0pre7try2+cvs20060117-0ubuntu8.1
devel

not-affected

edgy

released

2:0.99+1.0pre8-0ubuntu8.2
feisty

released

2:1.0~rc1-0ubuntu4
gutsy

not-affected

upstream

released

Показывать по

РелизСтатусПримечание
dapper

released

1.1.1+ubuntu2-7.7
devel

released

1.1.4-2ubuntu3
edgy

released

1.1.2+repacked1-0ubuntu3.4
feisty

released

1.1.4-2ubuntu3
gutsy

released

1.1.4-2ubuntu3
upstream

needs-triage

Показывать по

EPSS

Процентиль: 92%
0.09304
Низкий

7.6 High

CVSS2

Связанные уязвимости

nvd
больше 18 лет назад

The DMO_VideoDecoder_Open function in loader/dmo/DMO_VideoDecoder.c in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1387.

debian
больше 18 лет назад

The DMO_VideoDecoder_Open function in loader/dmo/DMO_VideoDecoder.c in ...

github
больше 3 лет назад

The DMO_VideoDecoder_Open function in loader/dmo/DMO_VideoDecoder.c in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1387.

EPSS

Процентиль: 92%
0.09304
Низкий

7.6 High

CVSS2