FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

mplayer -- Multiple integer overflows

Affected packages
mplayer < 0.99.7_12
mplayer-esound < 0.99.7_12
mplayer-gtk < 0.99.7_12
mplayer-gtk-esound < 0.99.7_12
mplayer-gtk2 < 0.99.7_12
mplayer-gtk2-esound < 0.99.7_12

Details

VuXML ID c7526a14-c4dc-11da-9699-00123ffe8333
Discovery 2006-03-29
Entry 2006-04-07

Secunia reports:

The vulnerabilities are caused due to integer overflow errors in "libmpdemux/asfheader.c" within the handling of an ASF file, and in "libmpdemux/aviheader.c" when parsing the "indx" chunk in an AVI file. This can be exploited to cause heap-based buffer overflows via a malicious ASF file, or via a AVI file with specially-crafted "wLongsPerEntry" and "nEntriesInUse" values in the "indx" chunk.

References

CVE Name CVE-2006-1502
URL http://secunia.com/advisories/19418/
URL http://www.xfocus.org/advisories/200603/11.html