CVE-2004-1311: Buffer Overflow
Integer overflow in the realsetupandgetheader function in real.c for Unix MPlayer 1.0pre5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a Real RTSP streaming media file with a -1 content-length field, which leads to a heap-based buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1311?
CVE-2004-1311 is classified as a medium severity vulnerability due to its potential to cause application crashes and arbitrary code execution.
How do I fix CVE-2004-1311?
To fix CVE-2004-1311, upgrade MPlayer to a version later than 1.0pre5 that contains the necessary patches addressing the integer overflow issue.
What type of attack does CVE-2004-1311 enable?
CVE-2004-1311 allows remote attackers to conduct denial of service attacks and potentially execute arbitrary code via crafted Real RTSP streaming files.
What is the affected software for CVE-2004-1311?
The affected software for CVE-2004-1311 is MPlayer version 1.0pre5.
Is CVE-2004-1311 still a risk today?
While CVE-2004-1311 is an older vulnerability, it can still pose a risk if outdated software versions are in use on systems.