CVE-2007-6718Improper Restriction of Operations within the Bounds of a Memory Buffer in Mplayer

Severity
5.0MEDIUMNVD
NVD4.3OSV7.6OSV4.3
EPSS
0.4%
top 36.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 20
Latest updateMay 17

Description

MPlayer, possibly 1.0rc1, allows remote attackers to cause a denial of service (SIGSEGV and application crash) via (1) a malformed MP3 file, as demonstrated by lol-mplayer.mp3; (2) a malformed Ogg Vorbis file, as demonstrated by lol-mplayer.ogg; (3) a malformed MPEG-1 file, as demonstrated by lol-mplayer.mpg; (4) a malformed MPEG-2 file, as demonstrated by lol-mplayer.m2v; (5) a malformed MPEG-4 AVI file, as demonstrated by lol-mplayer.avi; (6) a malformed FLAC file, as demonstrated by lol-mplay

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages5 packages

debiandebian/mplayer< mplayer 1.0~rc3+svn20100502-1 (bookworm)+1
Debianmplayer/mplayer< 1.0~rc3+svn20100502-1+7
NVDmplayer/mplayer1.0_rc1+19
debiandebian/ffmpeg< ffmpeg 7:2.4.1-1 (bookworm)
Debianffmpeg/ffmpeg< 7:2.4.1-1+3

🔴Vulnerability Details

4
GHSA
GHSA-w3rv-993w-f388: MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demonstrated by lol-vlc2022-05-17
GHSA
GHSA-r35q-7952-c6qv: MPlayer, possibly 12022-05-01
OSV
CVE-2007-6718: MPlayer, possibly 12008-10-20
OSV
CVE-2008-4610: MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demonstrated by lol-vlc2008-10-20

💥Exploits & PoCs

3
Exploit-DB
Microsoft Office 2007 - 'OGL.dll' ValidateBitmapInfo Bounds Check Failure (MS15-097)2015-09-16
Exploit-DB
Microsoft Office 2007 - BIFFRecord Length Use-After-Free2015-09-16
Exploit-DB
Microsoft Office 2007 - OLESSDirectyEntry.CreateTime Type Confusion2015-09-16

📋Vendor Advisories

2
Debian
CVE-2008-4610: ffmpeg - MPlayer allows remote attackers to cause a denial of service (application crash)...2008
Debian
CVE-2007-6718: mplayer - MPlayer, possibly 1.0rc1, allows remote attackers to cause a denial of service (...2007