CVE-2008-0630

Publication date 6 February 2008

Last updated 24 July 2024


Ubuntu priority

Buffer overflow in url.c in MPlayer 1.0rc2 and SVN before r25823 allows remote attackers to execute arbitrary code via a crafted URL that prevents the IPv6 parsing code from setting a pointer to NULL, which causes the buffer to be reused by the unescape code.

Status

Package Ubuntu Release Status
mplayer 7.10 gutsy
Fixed 2:1.0~rc1-0ubuntu13.2
7.04 feisty
Fixed 2:1.0~rc1-0ubuntu9.3
6.10 edgy
Fixed 2:0.99+1.0pre8-0ubuntu8.3
6.06 LTS dapper
Fixed 2:0.99+1.0pre7try2+cvs20060117-0ubuntu8.2

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
mplayer