CVE-2008-1558

Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote attackers to overwrite memory and execute arbitrary code via a large streamid SDP parameter. NOTE: this issue has been referred to as an integer overflow.

Date published : 2008-03-31

http://www.securityfocus.com/bid/28851

http://www.debian.org/security/2008/dsa-1552