CVE Vulnerabilities

CVE-2004-1187

Published: Jan 10, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.

Affected Software

NameVendorStart VersionEnd Version
MplayerMplayer0.90 (including)0.90 (including)
MplayerMplayer0.90_pre (including)0.90_pre (including)
MplayerMplayer0.90_rc (including)0.90_rc (including)
MplayerMplayer0.90_rc4 (including)0.90_rc4 (including)
MplayerMplayer0.91 (including)0.91 (including)
MplayerMplayer0.92 (including)0.92 (including)
MplayerMplayer0.92.1 (including)0.92.1 (including)
MplayerMplayer0.92_cvs (including)0.92_cvs (including)
MplayerMplayer1.0_pre1 (including)1.0_pre1 (including)
MplayerMplayer1.0_pre2 (including)1.0_pre2 (including)
MplayerMplayer1.0_pre3 (including)1.0_pre3 (including)
MplayerMplayer1.0_pre3try2 (including)1.0_pre3try2 (including)
MplayerMplayer1.0_pre4 (including)1.0_pre4 (including)
MplayerMplayer1.0_pre5 (including)1.0_pre5 (including)
MplayerMplayer1.0_pre5try1 (including)1.0_pre5try1 (including)
MplayerMplayer1.0_pre5try2 (including)1.0_pre5try2 (including)
MplayerMplayerhead_cvs (including)head_cvs (including)
XineXine0.9.8 (including)0.9.8 (including)
XineXine0.9.13 (including)0.9.13 (including)
XineXine0.9.18 (including)0.9.18 (including)
XineXine1_alpha (including)1_alpha (including)
XineXine1_beta1 (including)1_beta1 (including)
XineXine1_beta2 (including)1_beta2 (including)
XineXine1_beta3 (including)1_beta3 (including)
XineXine1_beta4 (including)1_beta4 (including)
XineXine1_beta5 (including)1_beta5 (including)
XineXine1_beta6 (including)1_beta6 (including)
XineXine1_beta7 (including)1_beta7 (including)
XineXine1_beta8 (including)1_beta8 (including)
XineXine1_beta9 (including)1_beta9 (including)
XineXine1_beta10 (including)1_beta10 (including)
XineXine1_beta11 (including)1_beta11 (including)
XineXine1_beta12 (including)1_beta12 (including)
XineXine1_rc0 (including)1_rc0 (including)
XineXine1_rc0a (including)1_rc0a (including)
XineXine1_rc1 (including)1_rc1 (including)
XineXine1_rc2 (including)1_rc2 (including)
XineXine1_rc3 (including)1_rc3 (including)
XineXine1_rc3a (including)1_rc3a (including)
XineXine1_rc3b (including)1_rc3b (including)
XineXine1_rc4 (including)1_rc4 (including)
XineXine1_rc5 (including)1_rc5 (including)
XineXine1_rc6 (including)1_rc6 (including)
XineXine1_rc6a (including)1_rc6a (including)
XineXine1_rc7 (including)1_rc7 (including)
XineXine1_rc8 (including)1_rc8 (including)
Xine-libXine0.9.8 (including)0.9.8 (including)
Xine-libXine0.9.13 (including)0.9.13 (including)
Xine-libXine0.99 (including)0.99 (including)
Xine-libXine1_alpha (including)1_alpha (including)
Xine-libXine1_beta1 (including)1_beta1 (including)
Xine-libXine1_beta2 (including)1_beta2 (including)
Xine-libXine1_beta3 (including)1_beta3 (including)
Xine-libXine1_beta4 (including)1_beta4 (including)
Xine-libXine1_beta5 (including)1_beta5 (including)
Xine-libXine1_beta6 (including)1_beta6 (including)
Xine-libXine1_beta7 (including)1_beta7 (including)
Xine-libXine1_beta8 (including)1_beta8 (including)
Xine-libXine1_beta9 (including)1_beta9 (including)
Xine-libXine1_beta10 (including)1_beta10 (including)
Xine-libXine1_beta11 (including)1_beta11 (including)
Xine-libXine1_beta12 (including)1_beta12 (including)
Xine-libXine1_rc0 (including)1_rc0 (including)
Xine-libXine1_rc1 (including)1_rc1 (including)
Xine-libXine1_rc2 (including)1_rc2 (including)
Xine-libXine1_rc3 (including)1_rc3 (including)
Xine-libXine1_rc3a (including)1_rc3a (including)
Xine-libXine1_rc3b (including)1_rc3b (including)
Xine-libXine1_rc3c (including)1_rc3c (including)
Xine-libXine1_rc4 (including)1_rc4 (including)
Xine-libXine1_rc5 (including)1_rc5 (including)
Xine-libXine1_rc6 (including)1_rc6 (including)
Xine-libXine1_rc6a (including)1_rc6a (including)
Xine-libXine1_rc7 (including)1_rc7 (including)
Xine-libUbuntudapper*
Xine-libUbuntudevel*
Xine-libUbuntuedgy*
Xine-libUbuntufeisty*

References