MEDIUM · 6.8

CVE-2007-1387

The DirectShow loader (loader/dshow/DS_VideoDecoder.c) in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers t...

Vulnerability Description

The DirectShow loader (loader/dshow/DS_VideoDecoder.c) in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1246.

CVSS Score

6.8

MEDIUM

AV:N/AC:H/Au:M/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
MplayerMplayer<= 1.0_rc1

References

FAQ

What is CVE-2007-1387?

CVE-2007-1387 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The DirectShow loader (loader/dshow/DS_VideoDecoder.c) in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers t...

How severe is CVE-2007-1387?

CVE-2007-1387 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-1387?

Check the references section above for vendor advisories and patch information. Affected products include: Mplayer Mplayer.