mplayer -- Multiple integer overflows

Affected packages
mplayer < 0.99.7_12
mplayer-esound < 0.99.7_12
mplayer-gtk < 0.99.7_12
mplayer-gtk-esound < 0.99.7_12
mplayer-gtk2 < 0.99.7_12
mplayer-gtk2-esound < 0.99.7_12


VuXML ID c7526a14-c4dc-11da-9699-00123ffe8333
Discovery 2006-03-29
Entry 2006-04-07

Secunia reports:

The vulnerabilities are caused due to integer overflow errors in "libmpdemux/asfheader.c" within the handling of an ASF file, and in "libmpdemux/aviheader.c" when parsing the "indx" chunk in an AVI file. This can be exploited to cause heap-based buffer overflows via a malicious ASF file, or via a AVI file with specially-crafted "wLongsPerEntry" and "nEntriesInUse" values in the "indx" chunk.


CVE Name CVE-2006-1502