Sploitus

CVE-2008-0486

1 known exploit for CVE-2008-0486

Array index vulnerability in libmpdemux/demux_audio.c in MPlayer 1.0rc2 and SVN before r25917, and possibly earlier versions, as used in Xine-lib 1.1.10, might allow remote attackers to execute arbitrary code via a crafted FLAC tag, which triggers a buffer overflow.

Affected products
Mplayer, Xine-Lib, Libmpdemux
Mplayer
= 1.02rc2
Xine Xine-lib
= 1.1.10
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
5.4% (92th percentile)
Weakness
CWE-189
NVD status
Modified
Published
2008-02-05
CVE-2008-0486 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2008-0486

Proof-of-concept code and exploit modules indexed by Sploitus