CVE-2004-1188 DetailsDescription The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values, a different vulnerability than CVE-2004-1187.
Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 SSVC
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration Affected Products Product Versions mplayer mplayer 0.90
0.90_pre
0.90_rc
0.90_rc4
0.91
0.92
0.92.1
0.92_cvs
1.0_pre1
1.0_pre2
1.0_pre3
1.0_pre3try2
1.0_pre4
1.0_pre5
1.0_pre5try1
1.0_pre5try2
head_cvs
Viewing 5 of 17 versions. View all CPE cpe:2.3:a:mplayer:mplayer:0.90:*:*:*:*:*:*:* cpe:2.3:a:mplayer:mplayer:0.90_pre:*:*:*:*:*:*:* cpe:2.3:a:mplayer:mplayer:0.90_rc:*:*:*:*:*:*:* cpe:2.3:a:mplayer:mplayer:0.90_rc4:*:*:*:*:*:*:* cpe:2.3:a:mplayer:mplayer:0.91:*:*:*:*:*:*:* cpe:2.3:a:mplayer:mplayer:0.92:*:*:*:*:*:*:* cpe:2.3:a:mplayer:mplayer:0.92.1:*:*:*:*:*:*:* cpe:2.3:a:mplayer:mplayer:0.92_cvs:*:*:*:*:*:*:* cpe:2.3:a:mplayer:mplayer:1.0_pre1:*:*:*:*:*:*:* cpe:2.3:a:mplayer:mplayer:1.0_pre2:*:*:*:*:*:*:* cpe:2.3:a:mplayer:mplayer:1.0_pre3:*:*:*:*:*:*:* cpe:2.3:a:mplayer:mplayer:1.0_pre3try2:*:*:*:*:*:*:* cpe:2.3:a:mplayer:mplayer:1.0_pre4:*:*:*:*:*:*:* cpe:2.3:a:mplayer:mplayer:1.0_pre5:*:*:*:*:*:*:* cpe:2.3:a:mplayer:mplayer:1.0_pre5try1:*:*:*:*:*:*:* cpe:2.3:a:mplayer:mplayer:1.0_pre5try2:*:*:*:*:*:*:* cpe:2.3:a:mplayer:mplayer:head_cvs:*:*:*:*:*:*:* Remediation No remediation found in references. xine xine 0.9.8
0.9.13
0.9.18
1_alpha
1_beta1
1_beta2
1_beta3
1_beta4
1_beta5
1_beta6
1_beta7
1_beta8
1_beta9
1_beta10
1_beta11
1_beta12
1_rc0
1_rc0a
1_rc1
1_rc2
1_rc3
1_rc3a
1_rc3b
1_rc4
1_rc5
1_rc6
1_rc6a
1_rc7
1_rc8
Viewing 5 of 29 versions. View all CPE cpe:2.3:a:xine:xine:0.9.8:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:0.9.13:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:0.9.18:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_alpha:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_beta1:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_beta2:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_beta3:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_beta4:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_beta5:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_beta6:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_beta7:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_beta8:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_beta9:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_beta10:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_beta11:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_beta12:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_rc0:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_rc0a:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_rc1:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_rc2:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_rc3:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_rc3a:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_rc3b:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_rc4:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_rc5:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_rc6:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_rc6a:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_rc7:*:*:*:*:*:*:* cpe:2.3:a:xine:xine:1_rc8:*:*:*:*:*:*:* Remediation No remediation found in references. xine xine-lib 0.9.8
0.9.13
0.99
1_alpha
1_beta1
1_beta2
1_beta3
1_beta4
1_beta5
1_beta6
1_beta7
1_beta8
1_beta9
1_beta10
1_beta11
1_beta12
1_rc0
1_rc1
1_rc2
1_rc3
1_rc3a
1_rc3b
1_rc3c
1_rc4
1_rc5
1_rc6
1_rc6a
1_rc7
Viewing 5 of 28 versions. View all CPE cpe:2.3:a:xine:xine-lib:0.9.8:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:0.9.13:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:0.99:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_alpha:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_beta1:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_beta2:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_beta3:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_beta4:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_beta5:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_beta6:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_beta7:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_beta8:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_beta9:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_beta10:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_beta11:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_beta12:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_rc0:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_rc1:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_rc2:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_rc3:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_rc3a:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_rc3b:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_rc3c:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_rc4:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_rc5:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_rc6:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_rc6a:*:*:*:*:*:*:* cpe:2.3:a:xine:xine-lib:1_rc7:*:*:*:*:*:*:* Remediation No remediation found in references. mandrakesoft mandrake linux 10.0
10.1
CPE cpe:2.3:o:mandrakesoft:mandrake_linux:10.0:*:*:*:*:*:*:* cpe:2.3:o:mandrakesoft:mandrake_linux:10.0:*:amd64:*:*:*:*:* cpe:2.3:o:mandrakesoft:mandrake_linux:10.1:*:*:*:*:*:*:* cpe:2.3:o:mandrakesoft:mandrake_linux:10.1:*:x86_64:*:*:*:*:* Remediation No remediation found in references.
Change History 6 change records found show changes