First published: Wed Dec 22 2004(Updated: )
Integer overflow in the real_setup_and_get_header function in real.c for Unix MPlayer 1.0pre5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a Real RTSP streaming media file with a -1 content-length field, which leads to a heap-based buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MPlayer | =1.0_pre5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1311 is classified as a medium severity vulnerability due to its potential to cause application crashes and arbitrary code execution.
To fix CVE-2004-1311, upgrade MPlayer to a version later than 1.0pre5 that contains the necessary patches addressing the integer overflow issue.
CVE-2004-1311 allows remote attackers to conduct denial of service attacks and potentially execute arbitrary code via crafted Real RTSP streaming files.
The affected software for CVE-2004-1311 is MPlayer version 1.0pre5.
While CVE-2004-1311 is an older vulnerability, it can still pose a risk if outdated software versions are in use on systems.