CVE-2006-6172

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/11/2006
Last modified:
09/04/2025

Description

Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp.c) for Real Media input plugin, as used in (1) xine/xine-lib, (2) MPlayer 1.0rc1 and earlier, and possibly others, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a rulebook with a large number of rulematches.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mplayer:mplayer:*:*:*:*:*:*:*:* 1.0_rc1 (including)
cpe:2.3:a:xine:real_media_input_plugin:*:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools