VDB
CVE-2006-6172
CVE-2006-6172
PUBLISHED
CVSS 7.5 HIGH
Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp.c) for Real Media input plugin, as used in (1) xine/xine-lib, (2) MPlayer 1.0rc1 and earlier, and possibly others, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a rulebook with a large number of rulematches.
EPSS 4.46% · 89.3th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
4.46%
89.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| xine | real_media_input_plugin | |
| mplayer | mplayer | 0 |
| n/a | n/a | * |
Timeline
- Nov 30, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 20, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- http://www.ubuntu.com/usn/usn-392-1 technical
- 23512 third-party-advisory
- 25555 third-party-advisory
- 24336 third-party-advisory
- 24339 third-party-advisory
- https://sourceforge.net/tracker/index.php?func=detail&aid=1603458&group_id=9655&atid=109655 url
- SSA:2006-357-05 vendor-advisory
- 23242 third-party-advisory
- GLSA-200612-02 vendor-advisory
- http://sourceforge.net/project/shownotes.php?release_id=468432 url
- 23567 third-party-advisory
- SUSE-SR:2006:028 vendor-advisory
- GLSA-200702-11 vendor-advisory
- 23249 third-party-advisory
- 23335 third-party-advisory
- 21435 vdb
- http://www.mplayerhq.hu/MPlayer/patches/asmrules_fix_20061231.diff url
- MDKSA-2006:224 vendor-advisory
- MDKSA-2007:112 vendor-advisory
- 23218 third-party-advisory
…and 5 more