CVE-2006-6172: Buffer overflow in asmrp.c

Bug #163291 reported by William Grant
256
Affects Status Importance Assigned to Milestone
mplayer (Ubuntu)
Fix Released
Undecided
William Grant
Dapper
Fix Released
Undecided
William Grant
Edgy
Fix Released
Undecided
William Grant

Bug Description

Binary package hint: mplayer

Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp.c) for Real Media input plugin, as used in (1) xine/xine-lib, (2) MPlayer 1.0rc1 and earlier, and possibly others, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a rulebook with a large number of rulematches.

Feisty was fixed in 2:1.0~rc1-0ubuntu1, so only Dapper and Edgy are vulnerable.

William Grant (wgrant)
Changed in mplayer:
assignee: nobody → fujitsu
status: New → Fix Released
assignee: nobody → fujitsu
status: New → In Progress
assignee: nobody → fujitsu
status: New → In Progress
Kees Cook (kees)
Changed in mplayer:
status: In Progress → Triaged
status: In Progress → Triaged
William Grant (wgrant)
Changed in mplayer:
status: Triaged → In Progress
William Grant (wgrant)
Changed in mplayer:
status: Triaged → In Progress
Kees Cook (kees)
Changed in mplayer:
status: In Progress → Fix Committed
status: In Progress → Fix Committed
William Grant (wgrant)
Changed in mplayer:
status: Fix Committed → Fix Released
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.