Summary
The remote host is missing an update to mplayer
announced via advisory DSA 1782-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201782-1
Insight
Several vulnerabilities have been discovered in mplayer, a movie player for Unix-like systems. The Common Vulnerabilities and Exposures project identifies the following problems:
CVE-2009-0385
It was discovered that watching a malformed 4X movie file could lead to the execution of arbitrary code.
CVE-2008-4866
It was discovered that multiple buffer overflows could lead to the execution of arbitrary code.
CVE-2008-5616
It was discovered that watching a malformed TwinVQ file could lead to the execution of arbitrary code.
For the oldstable distribution (etch), these problems have been fixed in version 1.0~rc1-12etch7.
For the stable distribution (lenny), mplayer links against ffmpeg-debian.
For the testing distribution (squeeze) and the unstable distribution (sid), mplayer links against ffmpeg-debian.
We recommend that you upgrade your mplayer packages.
Severity
Classification
-
CVE CVE-2008-4866, CVE-2008-5616, CVE-2009-0385 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities