CVE-2008-1558

Publication date 31 March 2008

Last updated 24 July 2024


Ubuntu priority

Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote attackers to overwrite memory and execute arbitrary code via a large streamid SDP parameter. NOTE: this issue has been referred to as an integer overflow.

Status

Package Ubuntu Release Status
mplayer 8.10 intrepid
Not affected
8.04 LTS hardy
Fixed 2:1.0~rc2-0ubuntu13
7.10 gutsy
Fixed 2:1.0~rc1-0ubuntu13.3
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper
Fixed 2:0.99+1.0pre7try2+cvs20060117-0ubuntu8.3