← Back

CVE-2004-1187

nvd nist
Published: Jan 10, 2005Modified: Apr 16, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.

Affected (78)

1 product
Mplayer
2 products
Xine
Xine Lib
1 product
Mandrake Linux
Configuration A
74 vulnerable
Vulnerable SoftwareAffected Versions
Mplayer
Version 0.90
Version 0.90_pre
Version 0.90_rc4
Version 0.90_rc
Version 0.91
Version 0.92.1
Version 0.92
Version 0.92_cvs
Version 1.0_pre1
Version 1.0_pre2
Version 1.0_pre3
Version 1.0_pre3try2
Version 1.0_pre4
Version 1.0_pre5
Version 1.0_pre5try1
Version 1.0_pre5try2
Version head_cvs
Xine
Version 0.9.13
Version 0.9.18
Version 0.9.8
Version 1_alpha
Version 1_beta10
Version 1_beta11
Version 1_beta12
Version 1_beta1
Version 1_beta2
Version 1_beta3
Version 1_beta4
Version 1_beta5
Version 1_beta6
Version 1_beta7
Version 1_beta8
Version 1_beta9
Version 1_rc0
Version 1_rc0a
Version 1_rc1
Version 1_rc2
Version 1_rc3
Version 1_rc3a
Version 1_rc3b
Version 1_rc4
Version 1_rc5
Version 1_rc6
Version 1_rc6a
Version 1_rc7
Version 1_rc8
Xine
Version 0.9.13
Version 0.9.8
Version 0.99
Version 1_alpha
Version 1_beta10
Version 1_beta11
Version 1_beta12
Version 1_beta1
Version 1_beta2
Version 1_beta3
Version 1_beta4
Version 1_beta5
Version 1_beta6
Version 1_beta7
Version 1_beta8
Version 1_beta9
Version 1_rc0
Version 1_rc1
Version 1_rc2
Version 1_rc3
Version 1_rc3a
Version 1_rc3b
Version 1_rc3c
Version 1_rc4
Version 1_rc5
Version 1_rc6
Version 1_rc6a
Version 1_rc7
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Mandrakesoft
Version 10.0
Version 10.0
Version 10.1
Version 10.1

Timeline

No history available yet.