CVE-2004-0386: Buffer Overflow
Published Apr 7, 2004
·Updated
Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.
Affected Software
17 affected components
MPlayer MPlayer=0.90
MPlayer MPlayer=0.90_pre
MPlayer MPlayer=0.90_rc
MPlayer MPlayer=0.91
MPlayer MPlayer=1.0_pre1
MPlayer MPlayer=1.0_pre2
MPlayer MPlayer=1.0_pre3
Gentoo Linux=0.5
Gentoo Linux=0.7
Gentoo Linux=1.1a
Gentoo Linux=1.2
Gentoo Linux=1.4
Gentoo Linux=1.4-rc1
Gentoo Linux=1.4-rc2
Gentoo Linux=1.4-rc3
Mandrakesoft Mandrake Linux=9.2
Mandrakesoft Mandrake Linux=10.0
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Apr 7, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0386?
CVE-2004-0386 is considered critical due to its potential for remote code execution.
2
How do I fix CVE-2004-0386?
To fix CVE-2004-0386, update MPlayer to version 1.0pre4 or later.
3
Which versions of MPlayer are affected by CVE-2004-0386?
CVE-2004-0386 affects MPlayer versions up to and including 1.0pre3, 0.90, and 0.91.
4
Can CVE-2004-0386 be exploited remotely?
Yes, CVE-2004-0386 can be exploited remotely via a long Location header.
5
What are the potential consequences of CVE-2004-0386?
The consequences of CVE-2004-0386 include the execution of arbitrary code on the affected systems.