Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

CVE-2004-1188

Disclosure Date: January 10, 2005
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values, a different vulnerability than CVE-2004-1187.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
None
Impact Score:
Unknown
Exploitability Score:
Unknown
Vector:
Unknown
Attack Vector (AV):
Unknown
Attack Complexity (AC):
Unknown
Privileges Required (PR):
Unknown
User Interaction (UI):
Unknown
Scope (S):
Unknown
Confidentiality (C):
Unknown
Integrity (I):
Unknown
Availability (A):
Unknown

General Information

Vendors

  • mandrakesoft,
  • mplayer,
  • xine

Products

  • mandrake linux 10.0,
  • mandrake linux 10.1,
  • mplayer 0.90,
  • mplayer 0.90 pre,
  • mplayer 0.90 rc,
  • mplayer 0.90 rc4,
  • mplayer 0.91,
  • mplayer 0.92,
  • mplayer 0.92 cvs,
  • mplayer 0.92.1,
  • mplayer 1.0 pre1,
  • mplayer 1.0 pre2,
  • mplayer 1.0 pre3,
  • mplayer 1.0 pre3try2,
  • mplayer 1.0 pre4,
  • mplayer 1.0 pre5,
  • mplayer 1.0 pre5try1,
  • mplayer 1.0 pre5try2,
  • mplayer head cvs,
  • xine 0.9.13,
  • xine 0.9.18,
  • xine 0.9.8,
  • xine 1 alpha,
  • xine 1 beta1,
  • xine 1 beta10,
  • xine 1 beta11,
  • xine 1 beta12,
  • xine 1 beta2,
  • xine 1 beta3,
  • xine 1 beta4,
  • xine 1 beta5,
  • xine 1 beta6,
  • xine 1 beta7,
  • xine 1 beta8,
  • xine 1 beta9,
  • xine 1 rc0,
  • xine 1 rc0a,
  • xine 1 rc1,
  • xine 1 rc2,
  • xine 1 rc3,
  • xine 1 rc3a,
  • xine 1 rc3b,
  • xine 1 rc4,
  • xine 1 rc5,
  • xine 1 rc6,
  • xine 1 rc6a,
  • xine 1 rc7,
  • xine 1 rc8,
  • xine-lib 0.9.13,
  • xine-lib 0.9.8,
  • xine-lib 0.99,
  • xine-lib 1 alpha,
  • xine-lib 1 beta1,
  • xine-lib 1 beta10,
  • xine-lib 1 beta11,
  • xine-lib 1 beta12,
  • xine-lib 1 beta2,
  • xine-lib 1 beta3,
  • xine-lib 1 beta4,
  • xine-lib 1 beta5,
  • xine-lib 1 beta6,
  • xine-lib 1 beta7,
  • xine-lib 1 beta8,
  • xine-lib 1 beta9,
  • xine-lib 1 rc0,
  • xine-lib 1 rc1,
  • xine-lib 1 rc2,
  • xine-lib 1 rc3,
  • xine-lib 1 rc3a,
  • xine-lib 1 rc3b,
  • xine-lib 1 rc3c,
  • xine-lib 1 rc4,
  • xine-lib 1 rc5,
  • xine-lib 1 rc6,
  • xine-lib 1 rc6a,
  • xine-lib 1 rc7
Technical Analysis