Title : MPlayer "demux_real_fill_buffer()" Integer Underflow Vulnerabilities VUPEN ID : VUPEN/ADV-2008-2703 CVE ID : CVE-2008-3827 CWE ID : CWE-191
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-09-30
Technical Description
Multiple vulnerabilities have been identified in MPlayer, which could be exploited by attackers to compromise a vulnerable system. These issues are caused by integer underflow errors in the "demux_real_fill_buffer()" [libmpdemux/demux_real.c] function when processing malformed data, which could allow attackers to crash an affected application or execute arbitrary code by tricking a user into opening a malicious video file.