First published: Wed Oct 01 2003(Updated: )
Multiple buffer overflows in asf_http_request of MPlayer before 0.92 allows remote attackers to execute arbitrary code via an ASX header with a long hostname.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MPlayer | =0.90 | |
MPlayer | =1.0_pre1 | |
MPlayer | =0.90_rc | |
MPlayer | =0.91 | |
MPlayer | =0.90_pre | |
MPlayer | =0.90_rc4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0835 is considered a critical vulnerability due to the potential for remote code execution.
To fix CVE-2003-0835, update MPlayer to version 0.92 or later.
CVE-2003-0835 affects MPlayer versions 0.90, 0.90_rc, 0.91, 0.90_pre, 1.0_pre1, and 0.90_rc4.
Yes, CVE-2003-0835 can be exploited remotely by sending a crafted ASX header with a long hostname.
CVE-2003-0835 is a buffer overflow vulnerability, allowing attackers to run arbitrary code.