CVE-2007-1387 - CERT CVE
ID CVE-2007-1387
Sažetak The DirectShow loader (loader/dshow/DS_VideoDecoder.c) in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1246.
Reference
CVSS
Base: 6.8
Impact: 10.0
Exploitability:3.2
Pristup
VektorSloženostAutentikacija
NETWORK HIGH MULTIPLE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE COMPLETE COMPLETE
CVSS vektor AV:N/AC:H/Au:M/C:C/I:C/A:C
Zadnje važnije ažuriranje 07-11-2023 - 02:00
Objavljeno 13-03-2007 - 19:19