← Back

CVE-2007-1387

nvd nist
Published: Mar 13, 2007Modified: Apr 23, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:H/Au:M/C:C/I:C/A:C
Exploitability: 3.2 / Impact: 10.0
Source: NVD

Description

The DirectShow loader (loader/dshow/DS_VideoDecoder.c) in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1246.

Affected (1)

Products: Mplayer: Mplayer
1 product
Mplayer
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.0_rc1

References (26)

Source: security@ubuntu.com
Source: security@ubuntu.com
Source: security@ubuntu.com
Vendor Advisory
Source: security@ubuntu.com
Source: security@ubuntu.com
Source: security@ubuntu.com
Source: security@ubuntu.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.