← Back

CVE-2007-4938

nvd nist
Published: Sep 18, 2007Modified: Apr 23, 2026

JSON object

Loading...
7.6
Vector
AV:N/AC:H/Au:N/C:C/I:C/A:C
Exploitability: 4.9 / Impact: 10.0
Source: NVD

Description

Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values, and a certain wLongsPerEntry value.

Affected (2)

Products: Mplayer: Mplayer · Sgi: Irix
1 product
Mplayer
1 product
Irix
Configuration A
2 vulnerable · 19 platform
Vulnerable SoftwareAffected Versions
Version 1.0_rc1
All versions
Running on/withPlatform Versions
Apple
Mac Os X
All versions
Hp
Hp Ux
All versions
Hp
Tru64
All versions
Ibm
Aix
All versions
Ibm
Os2
All versions
Linux
Linux Kernel
All versions
Mandrakesoft
Mandrake Linux
Version 2007.1
Mandrakesoft
Mandrake Linux
Version 2007.1
Mandrakesoft
Mandrake Linux
Version 2007
Mandrakesoft
Mandrake Linux
Version 2007
Microsoft
Windows 2000
All versions
Microsoft
Windows 2003 Server
All versions
Microsoft
Windows 98
All versions
Microsoft
Windows Me
All versions
Microsoft
Windows Nt
Version 4.0
Microsoft
Windows Xp
All versions
Santa Cruz Operation
Sco Unix
All versions
Sun
Solaris
All versions
Windriver
Bsdos
All versions

References (16)

Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.