Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade mplayer-gtk-esoundUpgrade mplayerUpgrade mplayer-esoundUpgrade mplayer-gtkUpgrade mplayer-gtk2-esoundUpgrade libxineUpgrade mplayer-gtk2 | Dec 10, 2025 | Dec 21, 2004 |
| Gentoo Linux | — | Upgrade media-libs/xine-lib. | Oct 30, 2017 | Jan 10, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub