Back to Database
Status published
Critical
CVE-2004-0386
Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and...
Vulnerability Description
Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-0386
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/11259
- http://www.mplayerhq.hu/homepage/design6/news.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15675
- http://marc.info/?l=bugtraq&m=108067020624076&w=2
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:026
- http://www.kb.cert.org/vuls/id/723910
- http://www.securityfocus.com/bid/10008
- http://www.securityfocus.com/archive/1/359025
- http://security.gentoo.org/glsa/glsa-200403-13.xml
More from mplayer
View All →CVE-2008-5616
Stack-based buffer overflow in the demux_open_vqf function in libmpdemux/demux_vqf.c in...
Critical
10
CVE-2008-4610
MPlayer allows remote attackers to cause a denial of service...
Medium
5
CVE-2008-3827
Multiple integer underflows in the Real demuxer (demux_real.c) in MPlayer...
Critical
9.3
CVE-2008-1558
Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in...
Critical
10
CVE-2008-0630
Buffer overflow in url.c in MPlayer 1.0rc2 and SVN before...
Medium
6.8
Affected Vendor
mplayer
View all reports →Affected Software
mplayer, linux, mandrake linux
Vulnerable Versions:
0.90, 0.90_pre, 0.90_rc, 0.91, 1.0_pre1, 1.0_pre2, 1.0_pre3, 0.5, 0.7, 1.1a, 1.2, 1.4, 9.2, 10.0
Timeline
Official Publish:
April 7th, 2004
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.