Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values, and a certain wLongsPerEntry value.
CVSS Vector
AV:N/AC:H/Au:N/C:C/I:C/A:CApple Mac Os X
OSAppleall versionsHP Ux
OSHpall versionsHP Tru64
OSHpall versionsIBM Aix
OSIbmall versionsIBM Os2
OSIbmall versionsLinux Kernel
OSLinuxall versionsMandrakesoft Mandrake Linux
OSMandrakesoft20072007.1Microsoft Windows 2000
OSMicrosoftall versionsMicrosoft Windows 2003 Server
OSMicrosoftall versionsMicrosoft Windows 98
OSMicrosoftall versionsMicrosoft Windows Me
OSMicrosoftall versionsMicrosoft Windows Nt
OSMicrosoft4.0Microsoft Windows Xp
OSMicrosoftall versionsMplayer
APPMplayer1.0_rc1Santa Cruz Operation Sco Unix
OSSanta Cruz Operationall versionsSgi Irix
OSSgiall versionsSun Solaris
OSSunall versionsWindriver Bsdos
OSWindriverall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDoSMemory
CWE
References
Related vulnerabilities
CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
CVE-2022-47986CRITICAL9.8⚠ KEVPL ✓same product
RCE przez YAML deserialization w IBM Aspera Faspex
CVE-2022-22954CRITICAL9.8⚠ KEVPL ✓same product
RCE w VMware Workspace ONE Access i Identity Manager poprzez server-side template injection
CVE-2021-1870CRITICAL9.8⚠ KEVPL ✓same product
Zdalne wykonanie kodu (RCE) w Apple iOS, iPadOS i macOS