CVE-2008-0485: Critical severity dvd player vulnerability
Published Feb 5, 2008
·Updated
Array index error in libmpdemux/demuxmov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbitrary code via a QuickTime MOV file with a crafted stsc atom tag.
Affected Software
1 affected component
MPlayer MPlayer<=1.02rc2
Event History
Feb 5, 2008
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0485?
CVE-2008-0485 is classified as having a high severity due to its potential to allow remote code execution.
2
How do I fix CVE-2008-0485?
To fix CVE-2008-0485, update MPlayer to version 1.0 rc3 or later, which addresses this vulnerability.
3
Who is affected by CVE-2008-0485?
CVE-2008-0485 affects users of MPlayer versions 1.0 rc2 and earlier.
4
What type of attack does CVE-2008-0485 facilitate?
CVE-2008-0485 facilitates remote attackers executing arbitrary code via specially crafted QuickTime MOV files.
5
When was CVE-2008-0485 disclosed?
CVE-2008-0485 was disclosed in February 2008.