CVE-2007-1387

Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 13 Mar 2007, 19:00
Last modified:07 Aug 2024, 12:50

Vulnerability Summary

Overall Risk (default)
medium
28/100
CVSS Score
6.8 MEDIUM
v2.0 (nvd)
EPSS Score
5.11% LOW
5% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

13 Mar 2007, 19:00
Published
Vulnerability first disclosed
07 Aug 2024, 12:50
Last Modified
Vulnerability information updated

Description

The DirectShow loader (loader/dshow/DS_VideoDecoder.c) in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1246.

CVSS Metrics

  • v2.0MEDIUMScore: 6.8AV:N/AC:H/Au:M/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 5.11% Percentile: 90%

Affected Systems

  • mplayermplayer

    ≤ 1.0_rc1

References (13)