Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp.c) for Real Media input plugin, as used in (1) xine/xine-lib, (2) MPlayer 1.0rc1 and earlier, and possibly others, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a rulebook with a large number of rulematches.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade mplayer | Jul 30, 2024 | Nov 30, 2006 |
| Freebsd | — | Upgrade mplayer-gtkUpgrade mplayer-esoundUpgrade mplayer-gtk2Upgrade libxineUpgrade mplayer-gtk2-esoundUpgrade mplayer-gtk-esoundUpgrade mplayer | Dec 10, 2025 | Dec 7, 2006 |
| Gentoo Linux | — | Upgrade media-libs/xine-lib.Upgrade media-video/mplayer. | Oct 30, 2017 | Nov 30, 2006 |
| Ubuntu | — | Upgrade libxine-main1Upgrade libxine1Upgrade libxine1c2 | Nov 8, 2024 | Nov 30, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub