Certain The MPlayer Project products are vulnerable to Buffer Overflow via readaviheader() of libmpdemux/aviheader.c . This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
{
"binaries": [
{
"binary_name": "mencoder",
"binary_version": "2:1.2.1-1ubuntu1.1+esm1"
},
{
"binary_name": "mplayer",
"binary_version": "2:1.2.1-1ubuntu1.1+esm1"
},
{
"binary_name": "mplayer-gui",
"binary_version": "2:1.2.1-1ubuntu1.1+esm1"
},
{
"binary_name": "mplayer2",
"binary_version": "2:1.2.1-1ubuntu1.1+esm1"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}
{
"binaries": [
{
"binary_name": "mencoder",
"binary_version": "2:1.3.0-8+deb10u1build0.20.04.1"
},
{
"binary_name": "mplayer",
"binary_version": "2:1.3.0-8+deb10u1build0.20.04.1"
},
{
"binary_name": "mplayer-gui",
"binary_version": "2:1.3.0-8+deb10u1build0.20.04.1"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_name": "mencoder",
"binary_version": "2:1.4+ds1-3ubuntu0.1"
},
{
"binary_name": "mplayer",
"binary_version": "2:1.4+ds1-3ubuntu0.1"
},
{
"binary_name": "mplayer-gui",
"binary_version": "2:1.4+ds1-3ubuntu0.1"
}
],
"availability": "No subscription required"
}