CVE-2008-0629
published 2008-02-06CVE-2008-0629: Buffer overflow in stream_cddb.c in MPlayer 1.0rc2 and SVN before r25824 allows remote user-assisted attackers to execute arbitrary code via a CDDB database…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.77%
84.8th percentile
Buffer overflow in stream_cddb.c in MPlayer 1.0rc2 and SVN before r25824 allows remote user-assisted attackers to execute arbitrary code via a CDDB database entry containing a long album title.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mplayer | < mplayer 1.0~rc2-8 (bookworm) | mplayer 1.0~rc2-8 (bookworm) |
| mplayer | mplayer | — | — |
| mplayer | mplayer | >= 0 < 1.0~rc2-8 | 1.0~rc2-8 |
| mplayer | mplayer | >= 0 < 1.0~rc2-8 | 1.0~rc2-8 |
| mplayer | mplayer | >= 0 < 1.0~rc2-8 | 1.0~rc2-8 |
| mplayer | mplayer | >= 0 < 1.0~rc2-8 | 1.0~rc2-8 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2008-0629: mplayer - Buffer overflow in stream_cddb.c in MPlayer 1.0rc2 and SVN before r25824 allows ...
vendor_debian·2008·CVSS 4.3
CVE-2008-0629 [MEDIUM] CVE-2008-0629: mplayer - Buffer overflow in stream_cddb.c in MPlayer 1.0rc2 and SVN before r25824 allows ...
Buffer overflow in stream_cddb.c in MPlayer 1.0rc2 and SVN before r25824 allows remote user-assisted attackers to execute arbitrary code via a CDDB database entry containing a long album title.
Scope: local
bookworm: resolved (fixed in 1.0~rc2-8)
bullseye: resolved (fixed in 1.0~rc2-8)
forky: resolved (fixed in 1.0~rc2-8)
sid: resolved (fixed in 1.0~rc2-8)
trixie: resolved (fixed in 1.0~rc2-8)
GHSA
GHSA-f6qx-7qq9-x6fq: Buffer overflow in stream_cddb
ghsa_unreviewed·2022-05-01
CVE-2008-0629 [MEDIUM] CWE-119 GHSA-f6qx-7qq9-x6fq: Buffer overflow in stream_cddb
Buffer overflow in stream_cddb.c in MPlayer 1.0rc2 and SVN before r25824 allows remote user-assisted attackers to execute arbitrary code via a CDDB database entry containing a long album title.
OSV
CVE-2008-0629: Buffer overflow in stream_cddb
osv·2008-02-06·CVSS 4.3
CVE-2008-0629 [MEDIUM] CVE-2008-0629: Buffer overflow in stream_cddb
Buffer overflow in stream_cddb.c in MPlayer 1.0rc2 and SVN before r25824 allows remote user-assisted attackers to execute arbitrary code via a CDDB database entry containing a long album title.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/28955http://secunia.com/advisories/28956http://secunia.com/advisories/29307http://security.gentoo.org/glsa/glsa-200803-16.xmlhttp://www.debian.org/security/2008/dsa-1496http://www.mandriva.com/security/advisories?name=MDVSA-2008:045http://www.mplayerhq.hu/design7/news.htmlhttp://www.securityfocus.com/bid/27765http://secunia.com/advisories/28955http://secunia.com/advisories/28956http://secunia.com/advisories/29307http://security.gentoo.org/glsa/glsa-200803-16.xmlhttp://www.debian.org/security/2008/dsa-1496http://www.mandriva.com/security/advisories?name=MDVSA-2008:045http://www.mplayerhq.hu/design7/news.htmlhttp://www.securityfocus.com/bid/27765
2008-02-06
Published