CVE-2006-6172
published 2006-11-30CVE-2006-6172: Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp.c) for Real Media input plugin, as used in (1) xine/xine-lib, (2)…
PriorityP433high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.35%
91.8th percentile
Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp.c) for Real Media input plugin, as used in (1) xine/xine-lib, (2) MPlayer 1.0rc1 and earlier, and possibly others, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a rulebook with a large number of rulematches.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mplayer | < mplayer 1.0~rc1-11 (bookworm) | mplayer 1.0~rc1-11 (bookworm) |
| mplayer | mplayer | <= 1.0_rc1 | — |
| mplayer | mplayer | >= 0 < 1.0~rc1-11 | 1.0~rc1-11 |
| mplayer | mplayer | >= 0 < 1.0~rc1-11 | 1.0~rc1-11 |
| mplayer | mplayer | >= 0 < 1.0~rc1-11 | 1.0~rc1-11 |
| mplayer | mplayer | >= 0 < 1.0~rc1-11 | 1.0~rc1-11 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q9x8-j998-f5qh: Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp
ghsa_unreviewed·2022-05-01
CVE-2006-6172 [HIGH] GHSA-q9x8-j998-f5qh: Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp
Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp.c) for Real Media input plugin, as used in (1) xine/xine-lib, (2) MPlayer 1.0rc1 and earlier, and possibly others, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a rulebook with a large number of rulematches.
OSV
CVE-2006-6172: Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp
osv·2006-11-30·CVSS 7.5
CVE-2006-6172 [HIGH] CVE-2006-6172: Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp
Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp.c) for Real Media input plugin, as used in (1) xine/xine-lib, (2) MPlayer 1.0rc1 and earlier, and possibly others, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a rulebook with a large number of rulematches.
Ubuntu
xine-lib vulnerability
vendor_ubuntu·2006-12-04
CVE-2006-6172 xine-lib vulnerability
Title: xine-lib vulnerability
Summary: xine-lib vulnerability
A buffer overflow was discovered in the Real Media input plugin in
xine-lib. If a user were tricked into loading a specially crafted
stream from a malicious server, the attacker could execute arbitrary
code with the user's privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2006-6172: mplayer - Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler ...
vendor_debian·2006·CVSS 7.5
CVE-2006-6172 [HIGH] CVE-2006-6172: mplayer - Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler ...
Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp.c) for Real Media input plugin, as used in (1) xine/xine-lib, (2) MPlayer 1.0rc1 and earlier, and possibly others, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a rulebook with a large number of rulematches.
Scope: local
bookworm: resolved (fixed in 1.0~rc1-11)
bullseye: resolved (fixed in 1.0~rc1-11)
forky: resolved (fixed in 1.0~rc1-11)
sid: resolved (fixed in 1.0~rc1-11)
trixie: resolved (fixed in 1.0~rc1-11)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/23218http://secunia.com/advisories/23242http://secunia.com/advisories/23249http://secunia.com/advisories/23301http://secunia.com/advisories/23335http://secunia.com/advisories/23512http://secunia.com/advisories/23567http://secunia.com/advisories/24336http://secunia.com/advisories/24339http://secunia.com/advisories/25555http://security.gentoo.org/glsa/glsa-200612-02.xmlhttp://security.gentoo.org/glsa/glsa-200702-11.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.433842http://sourceforge.net/project/shownotes.php?release_id=468432http://www.debian.org/security/2006/dsa-1244http://www.mandriva.com/security/advisories?name=MDKSA-2006:224http://www.mandriva.com/security/advisories?name=MDKSA-2007:112http://www.mplayerhq.hu/MPlayer/patches/asmrules_fix_20061231.diffhttp://www.mplayerhq.hu/design7/news.html#vuln14http://www.novell.com/linux/security/advisories/2006_28_sr.htmlhttp://www.securityfocus.com/bid/21435http://www.ubuntu.com/usn/usn-392-1http://www.vupen.com/english/advisories/2006/4824https://sourceforge.net/tracker/index.php?func=detail&aid=1603458&group_id=9655&atid=109655http://secunia.com/advisories/23218http://secunia.com/advisories/23242http://secunia.com/advisories/23249http://secunia.com/advisories/23301http://secunia.com/advisories/23335http://secunia.com/advisories/23512http://secunia.com/advisories/23567http://secunia.com/advisories/24336http://secunia.com/advisories/24339http://secunia.com/advisories/25555http://security.gentoo.org/glsa/glsa-200612-02.xmlhttp://security.gentoo.org/glsa/glsa-200702-11.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.433842http://sourceforge.net/project/shownotes.php?release_id=468432http://www.debian.org/security/2006/dsa-1244http://www.mandriva.com/security/advisories?name=MDKSA-2006:224http://www.mandriva.com/security/advisories?name=MDKSA-2007:112http://www.mplayerhq.hu/MPlayer/patches/asmrules_fix_20061231.diffhttp://www.mplayerhq.hu/design7/news.html#vuln14http://www.novell.com/linux/security/advisories/2006_28_sr.htmlhttp://www.securityfocus.com/bid/21435http://www.ubuntu.com/usn/usn-392-1http://www.vupen.com/english/advisories/2006/4824https://sourceforge.net/tracker/index.php?func=detail&aid=1603458&group_id=9655&atid=109655
2006-11-30
Published