CVE-2006-1502: Multiple integer overflows in asfheader.c

Bug #163293 reported by William Grant
254
Affects Status Importance Assigned to Milestone
mplayer (Ubuntu)
Fix Released
Undecided
Unassigned
Dapper
Fix Released
Undecided
William Grant

Bug Description

Binary package hint: mplayer

Multiple integer overflows in MPlayer 1.0pre7try2 allow remote attackers to cause a denial of service and trigger heap-based buffer overflows via (1) a certain ASF file handled by asfheader.c that causes the asf_descrambling function to be passed a negative integer after the conversion from a char to an int or (2) an AVI file with a crafted wLongsPerEntry or nEntriesInUse value in the indx chunk, which is handled in aviheader.c.

I finally located a patch at http://cvs.mandriva.com/cgi-bin/viewvc.cgi/SPECS/mplayer/mplayer-1.0pre7-CVE-2006-1502.patch?revision=1.1.2.1&view=markup&pathrev=r1_0-1_pre7_12_3_20060mdk.

William Grant (wgrant)
Changed in mplayer:
status: New → Fix Released
assignee: nobody → fujitsu
status: New → In Progress
Kees Cook (kees)
Changed in mplayer:
status: In Progress → Triaged
William Grant (wgrant)
Changed in mplayer:
status: Triaged → In Progress
Kees Cook (kees)
Changed in mplayer:
status: In Progress → Fix Committed
William Grant (wgrant)
Changed in mplayer:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.