ubuntu · CVE-2006-1502

Quick triage

Priority: medium Published: 2006-03-30 00:06:00 UTC Updated: 2025-07-17 16:38:07 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2006-1502 medium priority: Ubuntu including 1 source packages (mplayer), 5 status rows across 5 suites (dapper, edgy, feisty, gutsy, upstream): not-affected 3, released 2.

Description:

Multiple integer overflows in MPlayer 1.0pre7try2 allow remote attackers to cause a denial of service and trigger heap-based buffer overflows via (1) a certain ASF file handled by asfheader.c that causes the asf_descrambling function to be passed a negative integer after the conversion from a char to an int or (2) an AVI file with a crafted wLongsPerEntry or nEntriesInUse value in the indx chunk, which is handled in aviheader.c.

cvelogic Threat Intelligence