Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2004-1188

The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values, a different vulnerability than CVE-2004-1187.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.5%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2004-1188
  • Mplayer » Mplayer » Version: 0.90
    cpe:2.3:a:mplayer:mplayer:0.90
  • Mplayer » Mplayer » Version: 0.90_pre
    cpe:2.3:a:mplayer:mplayer:0.90_pre
  • Mplayer » Mplayer » Version: 0.90_rc
    cpe:2.3:a:mplayer:mplayer:0.90_rc
  • Mplayer » Mplayer » Version: 0.90_rc4
    cpe:2.3:a:mplayer:mplayer:0.90_rc4
  • Mplayer » Mplayer » Version: 0.91
    cpe:2.3:a:mplayer:mplayer:0.91
  • Mplayer » Mplayer » Version: 0.92
    cpe:2.3:a:mplayer:mplayer:0.92
  • Mplayer » Mplayer » Version: 0.92.1
    cpe:2.3:a:mplayer:mplayer:0.92.1
  • Mplayer » Mplayer » Version: 0.92_cvs
    cpe:2.3:a:mplayer:mplayer:0.92_cvs
  • Mplayer » Mplayer » Version: 1.0_pre1
    cpe:2.3:a:mplayer:mplayer:1.0_pre1
  • Mplayer » Mplayer » Version: 1.0_pre2
    cpe:2.3:a:mplayer:mplayer:1.0_pre2
  • Mplayer » Mplayer » Version: 1.0_pre3
    cpe:2.3:a:mplayer:mplayer:1.0_pre3
  • Mplayer » Mplayer » Version: 1.0_pre3try2
    cpe:2.3:a:mplayer:mplayer:1.0_pre3try2
  • Mplayer » Mplayer » Version: 1.0_pre4
    cpe:2.3:a:mplayer:mplayer:1.0_pre4
  • Mplayer » Mplayer » Version: 1.0_pre5
    cpe:2.3:a:mplayer:mplayer:1.0_pre5
  • Mplayer » Mplayer » Version: 1.0_pre5try1
    cpe:2.3:a:mplayer:mplayer:1.0_pre5try1
  • Mplayer » Mplayer » Version: 1.0_pre5try2
    cpe:2.3:a:mplayer:mplayer:1.0_pre5try2
  • Mplayer » Mplayer » Version: head_cvs
    cpe:2.3:a:mplayer:mplayer:head_cvs
  • Xine » Xine-Lib » Version: 0.9.13
    cpe:2.3:a:xine:xine-lib:0.9.13
  • Xine » Xine-Lib » Version: 0.9.8
    cpe:2.3:a:xine:xine-lib:0.9.8
  • Xine » Xine-Lib » Version: 0.99
    cpe:2.3:a:xine:xine-lib:0.99
  • Xine » Xine-Lib » Version: 1_alpha
    cpe:2.3:a:xine:xine-lib:1_alpha
  • Xine » Xine-Lib » Version: 1_beta1
    cpe:2.3:a:xine:xine-lib:1_beta1
  • Xine » Xine-Lib » Version: 1_beta10
    cpe:2.3:a:xine:xine-lib:1_beta10
  • Xine » Xine-Lib » Version: 1_beta11
    cpe:2.3:a:xine:xine-lib:1_beta11
  • Xine » Xine-Lib » Version: 1_beta12
    cpe:2.3:a:xine:xine-lib:1_beta12
  • Xine » Xine-Lib » Version: 1_beta2
    cpe:2.3:a:xine:xine-lib:1_beta2
  • Xine » Xine-Lib » Version: 1_beta3
    cpe:2.3:a:xine:xine-lib:1_beta3
  • Xine » Xine-Lib » Version: 1_beta4
    cpe:2.3:a:xine:xine-lib:1_beta4
  • Xine » Xine-Lib » Version: 1_beta5
    cpe:2.3:a:xine:xine-lib:1_beta5
  • Xine » Xine-Lib » Version: 1_beta6
    cpe:2.3:a:xine:xine-lib:1_beta6
  • Xine » Xine-Lib » Version: 1_beta7
    cpe:2.3:a:xine:xine-lib:1_beta7
  • Xine » Xine-Lib » Version: 1_beta8
    cpe:2.3:a:xine:xine-lib:1_beta8
  • Xine » Xine-Lib » Version: 1_beta9
    cpe:2.3:a:xine:xine-lib:1_beta9
  • Xine » Xine-Lib » Version: 1_rc0
    cpe:2.3:a:xine:xine-lib:1_rc0
  • Xine » Xine-Lib » Version: 1_rc1
    cpe:2.3:a:xine:xine-lib:1_rc1
  • Xine » Xine-Lib » Version: 1_rc2
    cpe:2.3:a:xine:xine-lib:1_rc2
  • Xine » Xine-Lib » Version: 1_rc3
    cpe:2.3:a:xine:xine-lib:1_rc3
  • Xine » Xine-Lib » Version: 1_rc3a
    cpe:2.3:a:xine:xine-lib:1_rc3a
  • Xine » Xine-Lib » Version: 1_rc3b
    cpe:2.3:a:xine:xine-lib:1_rc3b
  • Xine » Xine-Lib » Version: 1_rc3c
    cpe:2.3:a:xine:xine-lib:1_rc3c
  • Xine » Xine-Lib » Version: 1_rc4
    cpe:2.3:a:xine:xine-lib:1_rc4
  • Xine » Xine-Lib » Version: 1_rc5
    cpe:2.3:a:xine:xine-lib:1_rc5
  • Xine » Xine-Lib » Version: 1_rc6
    cpe:2.3:a:xine:xine-lib:1_rc6
  • Xine » Xine-Lib » Version: 1_rc6a
    cpe:2.3:a:xine:xine-lib:1_rc6a
  • Xine » Xine-Lib » Version: 1_rc7
    cpe:2.3:a:xine:xine-lib:1_rc7
  • Xine » Xine » Version: 0.9.13
    cpe:2.3:a:xine:xine:0.9.13
  • Xine » Xine » Version: 0.9.18
    cpe:2.3:a:xine:xine:0.9.18
  • Xine » Xine » Version: 0.9.8
    cpe:2.3:a:xine:xine:0.9.8
  • Xine » Xine » Version: 1_alpha
    cpe:2.3:a:xine:xine:1_alpha
  • Xine » Xine » Version: 1_beta1
    cpe:2.3:a:xine:xine:1_beta1
  • Xine » Xine » Version: 1_beta10
    cpe:2.3:a:xine:xine:1_beta10
  • Xine » Xine » Version: 1_beta11
    cpe:2.3:a:xine:xine:1_beta11
  • Xine » Xine » Version: 1_beta12
    cpe:2.3:a:xine:xine:1_beta12
  • Xine » Xine » Version: 1_beta2
    cpe:2.3:a:xine:xine:1_beta2
  • Xine » Xine » Version: 1_beta3
    cpe:2.3:a:xine:xine:1_beta3
  • Xine » Xine » Version: 1_beta4
    cpe:2.3:a:xine:xine:1_beta4
  • Xine » Xine » Version: 1_beta5
    cpe:2.3:a:xine:xine:1_beta5
  • Xine » Xine » Version: 1_beta6
    cpe:2.3:a:xine:xine:1_beta6
  • Xine » Xine » Version: 1_beta7
    cpe:2.3:a:xine:xine:1_beta7
  • Xine » Xine » Version: 1_beta8
    cpe:2.3:a:xine:xine:1_beta8
  • Xine » Xine » Version: 1_beta9
    cpe:2.3:a:xine:xine:1_beta9
  • Xine » Xine » Version: 1_rc0
    cpe:2.3:a:xine:xine:1_rc0
  • Xine » Xine » Version: 1_rc0a
    cpe:2.3:a:xine:xine:1_rc0a
  • Xine » Xine » Version: 1_rc1
    cpe:2.3:a:xine:xine:1_rc1
  • Xine » Xine » Version: 1_rc2
    cpe:2.3:a:xine:xine:1_rc2
  • Xine » Xine » Version: 1_rc3
    cpe:2.3:a:xine:xine:1_rc3
  • Xine » Xine » Version: 1_rc3a
    cpe:2.3:a:xine:xine:1_rc3a
  • Xine » Xine » Version: 1_rc3b
    cpe:2.3:a:xine:xine:1_rc3b
  • Xine » Xine » Version: 1_rc4
    cpe:2.3:a:xine:xine:1_rc4
  • Xine » Xine » Version: 1_rc5
    cpe:2.3:a:xine:xine:1_rc5
  • Xine » Xine » Version: 1_rc6
    cpe:2.3:a:xine:xine:1_rc6
  • Xine » Xine » Version: 1_rc6a
    cpe:2.3:a:xine:xine:1_rc6a
  • Xine » Xine » Version: 1_rc7
    cpe:2.3:a:xine:xine:1_rc7
  • Xine » Xine » Version: 1_rc8
    cpe:2.3:a:xine:xine:1_rc8
  • Mandrakesoft » Mandrake Linux » Version: 10.0
    cpe:2.3:o:mandrakesoft:mandrake_linux:10.0
  • Mandrakesoft » Mandrake Linux » Version: 10.1
    cpe:2.3:o:mandrakesoft:mandrake_linux:10.1


Contact Us

Shodan ® - All rights reserved