Vulnerability Description
Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values, and a certain wLongsPerEntry value.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Mac Os X | All versions |
| Hp | Hp-Ux | All versions |
| Hp | Tru64 | All versions |
| Ibm | Aix | All versions |
| Ibm | Os2 | All versions |
| Linux | Linux Kernel | All versions |
| Mandrakesoft | Mandrake Linux | 2007 |
| Microsoft | Windows 2000 | All versions |
| Microsoft | Windows 2003 Server | All versions |
| Microsoft | Windows 98 | All versions |
| Microsoft | Windows Me | All versions |
| Microsoft | Windows Nt | 4.0 |
| Microsoft | Windows Xp | All versions |
| Santa Cruz Operation | Sco Unix | All versions |
| Sun | Solaris | All versions |
| Windriver | Bsdos | All versions |
| Mplayer | Mplayer | 1.0_rc1 |
| Sgi | Irix | All versions |
Related Weaknesses (CWE)
References
- http://osvdb.org/45940
- http://secunia.com/advisories/27016Vendor Advisory
- http://securityreason.com/securityalert/3144
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:192
- http://www.securityfocus.com/archive/1/479222/100/0/threaded
- http://www.securityfocus.com/bid/25648Exploit
- http://www.vulnhunt.com/advisories/CAL-20070912-1_Multiple_vendor_produce_handliExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36581
- http://osvdb.org/45940
- http://secunia.com/advisories/27016Vendor Advisory
- http://securityreason.com/securityalert/3144
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:192
- http://www.securityfocus.com/archive/1/479222/100/0/threaded
- http://www.securityfocus.com/bid/25648Exploit
- http://www.vulnhunt.com/advisories/CAL-20070912-1_Multiple_vendor_produce_handliExploit
FAQ
What is CVE-2007-4938?
CVE-2007-4938 is a vulnerability with a CVSS score of 7.6 (HIGH). Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .av...
How severe is CVE-2007-4938?
CVE-2007-4938 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-4938?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Mac Os X, Hp Hp-Ux, Hp Tru64, Ibm Aix, Ibm Os2.