>> MPlayer and Xine-lib "DMO_VideoDecoder()" and "DS_VideoDecoder_Open()" Issues
Title : MPlayer and Xine-lib "DMO_VideoDecoder()" and "DS_VideoDecoder_Open()" Issues VUPEN ID : VUPEN/ADV-2007-0794 CVE ID : CVE-2007-1246 - CVE-2007-1387
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-03-01
Technical Description
Two vulnerabilities have been identified in MPlayer, which could be exploited by remote attackers to execute arbitrary commands. These issues are due to buffer overflow errors within the "DMO_VideoDecoder()" [loader/dmo/DMO_VideoDecoder.c] and "DS_VideoDecoder_Open()" [loader/dshow/DS_VideoDecoder.c] functions that does not validate certain values before being copied into an insufficiently sized buffer via a "memcpy()" call, which could be exploited by attackers to crash an affected application or compromise a vulnerable system by tricking a user into opening a specially crafted video file.