CVE-2007-1387: Buffer Overflow
The DirectShow loader (loader/dshow/DSVideoDecoder.c) in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1246.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1387?
CVE-2007-1387 has a medium severity rating due to the potential for remote attackers to execute arbitrary code via a buffer overflow.
How do I fix CVE-2007-1387?
To fix CVE-2007-1387, upgrade MPlayer to a version later than 1.0rc1 that addresses this vulnerability.
What versions of MPlayer are affected by CVE-2007-1387?
MPlayer versions up to and including 1.0rc1 are vulnerable to CVE-2007-1387.
What type of vulnerabilities does CVE-2007-1387 represent?
CVE-2007-1387 represents a buffer overflow vulnerability that requires user assistance for exploitation.
Can CVE-2007-1387 be exploited remotely?
CVE-2007-1387 can be exploited remotely, but requires user intervention to trigger the buffer overflow.