CVE-2006-1502

Publication date 30 March 2006

Last updated 17 July 2025


Ubuntu priority

Description

Multiple integer overflows in MPlayer 1.0pre7try2 allow remote attackers to cause a denial of service and trigger heap-based buffer overflows via (1) a certain ASF file handled by asfheader.c that causes the asf_descrambling function to be passed a negative integer after the conversion from a char to an int or (2) an AVI file with a crafted wLongsPerEntry or nEntriesInUse value in the indx chunk, which is handled in aviheader.c.

Status

Package Ubuntu Release Status
mplayer 7.10 gutsy
Not affected
7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Fixed 2:0.99+1.0pre7try2+cvs20060117-0ubuntu8.1