CVE-2022-38865Divide By Zero in Mencoder

CWE-369Divide By Zero7 documents6 sources
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 81.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 15
Latest updateFeb 27

Description

Certain The MPlayer Project products are vulnerable to Divide By Zero via the function demux_avi_read_packet of libmpdemux/demux_avi.c. This affects mplyer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDmplayerhq/mencodersvn-r38374-13.0.1
Debianmplayer/mplayer< 2:1.4+ds1-1+deb11u1+3
Ubuntumplayer/mplayer< 2:1.3.0-7ubuntu0.2+3
NVDmplayerhq/mplayersvn-r38374-13.0.1

Also affects: Debian Linux 10.0

🔴Vulnerability Details

4
OSV
mplayer vulnerabilities2023-02-27
GHSA
GHSA-hc88-g42g-7pc8: Certain The MPlayer Project products are vulnerable to Divide By Zero via the function demux_avi_read_packet of libmpdemux/demux_avi2022-09-16
OSV
CVE-2022-38865: Certain The MPlayer Project products are vulnerable to Divide By Zero via the function demux_avi_read_packet of libmpdemux/demux_avi2022-09-15
CVEList
CVE-2022-38865: Certain The MPlayer Project products are vulnerable to Divide By Zero via the function demux_avi_read_packet of libmpdemux/demux_avi2022-09-15

📋Vendor Advisories

2
Ubuntu
MPlayer vulnerabilities2023-02-27
Debian
CVE-2022-38865: mplayer - Certain The MPlayer Project products are vulnerable to Divide By Zero via the fu...2022
CVE-2022-38865 — Divide By Zero in Mplayerhq Mencoder | cvebase