Unrated severityNVD Advisory· Published Dec 17, 2008· Updated Apr 23, 2026
CVE-2008-5616
CVE-2008-5616
Description
Stack-based buffer overflow in the demux_open_vqf function in libmpdemux/demux_vqf.c in MPlayer 1.0 rc2 before r28150 allows remote attackers to execute arbitrary code via a malformed TwinVQ file.
Affected products
20cpe:2.3:a:mplayer:mplayer:*:*:*:*:*:*:*:*+ 19 more
- cpe:2.3:a:mplayer:mplayer:*:*:*:*:*:*:*:*range: <=1.0_rc1
- cpe:2.3:a:mplayer:mplayer:0.90:*:*:*:*:*:*:*
- cpe:2.3:a:mplayer:mplayer:0.90_pre:*:*:*:*:*:*:*
- cpe:2.3:a:mplayer:mplayer:0.90_rc:*:*:*:*:*:*:*
- cpe:2.3:a:mplayer:mplayer:0.90_rc4:*:*:*:*:*:*:*
- cpe:2.3:a:mplayer:mplayer:0.91:*:*:*:*:*:*:*
- cpe:2.3:a:mplayer:mplayer:0.92:*:*:*:*:*:*:*
- cpe:2.3:a:mplayer:mplayer:0.92.1:*:*:*:*:*:*:*
- cpe:2.3:a:mplayer:mplayer:0.92_cvs:*:*:*:*:*:*:*
- cpe:2.3:a:mplayer:mplayer:1.0_pre1:*:*:*:*:*:*:*
- cpe:2.3:a:mplayer:mplayer:1.0_pre2:*:*:*:*:*:*:*
- cpe:2.3:a:mplayer:mplayer:1.0_pre3:*:*:*:*:*:*:*
- cpe:2.3:a:mplayer:mplayer:1.0_pre3try2:*:*:*:*:*:*:*
- cpe:2.3:a:mplayer:mplayer:1.0_pre4:*:*:*:*:*:*:*
- cpe:2.3:a:mplayer:mplayer:1.0_pre5:*:*:*:*:*:*:*
- cpe:2.3:a:mplayer:mplayer:1.0_pre5try1:*:*:*:*:*:*:*
- cpe:2.3:a:mplayer:mplayer:1.0_pre5try2:*:*:*:*:*:*:*
- cpe:2.3:a:mplayer:mplayer:1.0_pre6:*:*:*:*:*:*:*
- cpe:2.3:a:mplayer:mplayer:1.0_pre7:*:*:*:*:*:*:*
- cpe:2.3:a:mplayer:mplayer:1.0_pre7try2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- secunia.com/advisories/33136nvdVendor Advisory
- secunia.com/advisories/34845nvd
- svn.mplayerhq.hu/mplayer/branches/1.0rc2/libmpdemux/demux_vqf.cnvd
- svn.mplayerhq.hu/mplayer/branches/1.0rc2/libmpdemux/demux_vqf.cnvd
- trapkit.de/advisories/TKADV2008-014.txtnvd
- www.debian.org/security/2009/dsa-1782nvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/archive/1/499214/100/0/threadednvd
- www.securityfocus.com/bid/32822nvd
News mentions
0No linked articles in our index yet.