Multiple buffer overflows in the Real-Time Streaming Protocol (RTSP) client for (1) MPlayer before 1.0pre4 and (2) xine lib (xine-lib) before 1-rc4, when playing Real RTSP (realrtsp) streams, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (a) long URLs, (b) long Real server responses, or (c) long Real Data Transport (RDT) packets.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mplayer | Mplayer | 1.0_pre3try2 (including) | 1.0_pre3try2 (including) |
Xine-lib | Xine | 1_beta1 (including) | 1_beta1 (including) |
Xine-lib | Xine | 1_beta2 (including) | 1_beta2 (including) |
Xine-lib | Xine | 1_beta3 (including) | 1_beta3 (including) |
Xine-lib | Xine | 1_beta4 (including) | 1_beta4 (including) |
Xine-lib | Xine | 1_beta5 (including) | 1_beta5 (including) |
Xine-lib | Xine | 1_beta6 (including) | 1_beta6 (including) |
Xine-lib | Xine | 1_beta7 (including) | 1_beta7 (including) |
Xine-lib | Xine | 1_beta8 (including) | 1_beta8 (including) |
Xine-lib | Xine | 1_beta9 (including) | 1_beta9 (including) |
Xine-lib | Xine | 1_beta10 (including) | 1_beta10 (including) |
Xine-lib | Xine | 1_beta11 (including) | 1_beta11 (including) |
Xine-lib | Xine | 1_rc2 (including) | 1_rc2 (including) |
Xine-lib | Xine | 1_rc3a (including) | 1_rc3a (including) |
Xine-lib | Xine | 1_rc3b (including) | 1_rc3b (including) |
Xine-lib | Xine | 1_rc3c (including) | 1_rc3c (including) |