CVE-2008-3827
NONE EPSS 95.3%
Published Sep 29, 200817y ago · Modified Jun 16, 20262w ago
Published Sep 29, 2008 17y ago
Last Modified Jun 16, 2026 2w ago
Description
Multiple integer underflows in the Real demuxer (demux_real.c) in MPlayer 1.0_rc2 and earlier allow remote attackers to cause a denial of service (process termination) and possibly execute arbitrary code via a crafted video file that causes the stream_read function to read or write arbitrary memory.
Threat Intelligence
EPSS Exploit Probability
95.3% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-189
Affected Products 21
| Vendor | Product | Version | Range |
|---|---|---|---|
| mplayer | mplayer | * | ≤1.0_rc2 |
| mplayer | mplayer | 0.90 | any |
| mplayer | mplayer | 0.90_pre | any |
| mplayer | mplayer | 0.90_rc | any |
| mplayer | mplayer | 0.90_rc4 | any |
| mplayer | mplayer | 0.91 | any |
| mplayer | mplayer | 0.92 | any |
| mplayer | mplayer | 0.92.1 | any |
| mplayer | mplayer | 0.92_cvs | any |
| mplayer | mplayer | 1.0_pre1 | any |
| mplayer | mplayer | 1.0_pre2 | any |
| mplayer | mplayer | 1.0_pre3 | any |
| mplayer | mplayer | 1.0_pre3try2 | any |
| mplayer | mplayer | 1.0_pre4 | any |
| mplayer | mplayer | 1.0_pre5 | any |
| mplayer | mplayer | 1.0_pre5try1 | any |
| mplayer | mplayer | 1.0_pre5try2 | any |
| mplayer | mplayer | 1.0_pre6 | any |
| mplayer | mplayer | 1.0_pre7 | any |
| mplayer | mplayer | 1.0_pre7try2 | any |
| mplayer | mplayer | 1.0_rc1 | any |
References 11
- secunia.com http://secunia.com/advisories/32045
- secunia.com http://secunia.com/advisories/32153
- securityreason.com http://securityreason.com/securityalert/4326
- svn.mplayerhq.hu http://svn.mplayerhq.hu/mplayer/trunk/libmpdemux/demux_real.c?r1=27314&r2=27675
- debian.org http://www.debian.org/security/2008/dsa-1644
- mandriva.com http://www.mandriva.com/security/advisories?name=MDVSA-2008:219
- ocert.org http://www.ocert.org/advisories/ocert-2008-013.html
- securityfocus.com http://www.securityfocus.com/archive/1/496806/100/0/threaded
- securityfocus.com http://www.securityfocus.com/bid/31473
- securitytracker.com http://www.securitytracker.com/id?1020952
- vupen.com http://www.vupen.com/english/advisories/2008/2703
Remediation
- ocert.org http://www.ocert.org/advisories/ocert-2008-013.html