CVE Vulnerabilities

CVE-2004-0433

Published: Aug 18, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Multiple buffer overflows in the Real-Time Streaming Protocol (RTSP) client for (1) MPlayer before 1.0pre4 and (2) xine lib (xine-lib) before 1-rc4, when playing Real RTSP (realrtsp) streams, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (a) long URLs, (b) long Real server responses, or (c) long Real Data Transport (RDT) packets.

Affected Software

Name Vendor Start Version End Version
Mplayer Mplayer 1.0_pre3try2 (including) 1.0_pre3try2 (including)
Xine-lib Xine 1_beta1 (including) 1_beta1 (including)
Xine-lib Xine 1_beta2 (including) 1_beta2 (including)
Xine-lib Xine 1_beta3 (including) 1_beta3 (including)
Xine-lib Xine 1_beta4 (including) 1_beta4 (including)
Xine-lib Xine 1_beta5 (including) 1_beta5 (including)
Xine-lib Xine 1_beta6 (including) 1_beta6 (including)
Xine-lib Xine 1_beta7 (including) 1_beta7 (including)
Xine-lib Xine 1_beta8 (including) 1_beta8 (including)
Xine-lib Xine 1_beta9 (including) 1_beta9 (including)
Xine-lib Xine 1_beta10 (including) 1_beta10 (including)
Xine-lib Xine 1_beta11 (including) 1_beta11 (including)
Xine-lib Xine 1_rc2 (including) 1_rc2 (including)
Xine-lib Xine 1_rc3a (including) 1_rc3a (including)
Xine-lib Xine 1_rc3b (including) 1_rc3b (including)
Xine-lib Xine 1_rc3c (including) 1_rc3c (including)

References