Multiple integer underflows in the Real demuxer (demux_real.c) in MPlayer 1.0_rc2 and earlier allow remote attackers to cause a denial of service (process termination) and possibly execute arbitrary code via a crafted video file that causes the stream_read function to read or write arbitrary memory.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade mplayer | Jul 30, 2024 | Sep 29, 2008 |
| Freebsd | — | Upgrade mplayer-gtk-esoundUpgrade mplayerUpgrade mplayer-gtk2Upgrade mplayer-gtk2-esoundUpgrade mplayer-esoundUpgrade mplayer-gtk | Dec 10, 2025 | Oct 1, 2008 |
| Gentoo Linux | — | Upgrade media-video/mplayer. | Oct 30, 2017 | Sep 29, 2008 |
| Ubuntu | — | Upgrade mplayer | Nov 19, 2024 | Sep 29, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub