Summary
The remote host is missing an update to mplayer
announced via advisory DSA 1496-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201496-1
Insight
Several buffer overflows have been discovered in the MPlayer movie player, which might lead to the execution of arbitrary code. The Common Vulnerabilities and Exposures project identifies the following problems:
CVE-2008-0485
Felipe Manzano and Anibal Sacco discovered a buffer overflow in the demuxer for MOV files.
CVE-2008-0486
Reimar Doeffinger discovered a buffer overflow in the FLAC header parsing.
CVE-2008-0629
Adam Bozanich discovered a buffer overflow in the CDDB access code.
CVE-2008-0630
Adam Bozanich discovered a buffer overflow in URL parsing.
For the stable distribution (etch), these problems have been fixed in version 1.0~rc1-12etch2.
The old stable distribution (sarge) doesn't contain mplayer.
We recommend that you upgrade your mplayer packages.
Severity
Classification
-
CVE CVE-2008-0485, CVE-2008-0486, CVE-2008-0629, CVE-2008-0630 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities