CVE-2006-6172Improper Restriction of Operations within the Bounds of a Memory Buffer in Mplayer

5 documents5 sources
Severity
7.5HIGHNVD
EPSS
4.5%
top 10.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 30
Latest updateMay 1

Description

Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp.c) for Real Media input plugin, as used in (1) xine/xine-lib, (2) MPlayer 1.0rc1 and earlier, and possibly others, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a rulebook with a large number of rulematches.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/mplayer< mplayer 1.0~rc1-11 (bookworm)
Debianmplayer/mplayer< 1.0~rc1-11+3
NVDmplayer/mplayer1.0_rc1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-q9x8-j998-f5qh: Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp2022-05-01
OSV
CVE-2006-6172: Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp2006-11-30

📋Vendor Advisories

2
Ubuntu
xine-lib vulnerability2006-12-04
Debian
CVE-2006-6172: mplayer - Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler ...2006