CVE-2004-1187: Buffer Overflow
Heap-based buffer overflow in the pnmgetchunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNATAG values, a different vulnerability than CVE-2004-1188.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1187?
CVE-2004-1187 is considered a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary code.
How do I fix CVE-2004-1187?
To fix CVE-2004-1187, update xine or MPlayer to versions that include the patch addressing this vulnerability.
What software is affected by CVE-2004-1187?
CVE-2004-1187 affects several versions of xine and MPlayer, particularly versions 0.9.18, 1_rc0a, and others up to 0.92.1.
What is the nature of the vulnerability in CVE-2004-1187?
The vulnerability in CVE-2004-1187 is a heap-based buffer overflow in the pnm_get_chunk function, which can be exploited through long PNA_TAG values.
Can I still use xine or MPlayer if they are affected by CVE-2004-1187?
It is advised not to use affected versions of xine or MPlayer until you have applied the necessary updates or patches to mitigate CVE-2004-1187.