CVE-2004-1188
Summary
| CVE | CVE-2004-1188 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-01-10 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values, a different vulnerability than CVE-2004-1187. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Mandrakesoft | Mandrake Linux | 10.0 | All | All | All |
| Operating System | Mandrakesoft | Mandrake Linux | 10.0 | All | amd64 | All |
| Operating System | Mandrakesoft | Mandrake Linux | 10.1 | All | All | All |
| Operating System | Mandrakesoft | Mandrake Linux | 10.1 | All | x86_64 | All |
| Application | Mplayer | Mplayer | 0.90 | All | All | All |
| Application | Mplayer | Mplayer | 0.90_pre | All | All | All |
| Application | Mplayer | Mplayer | 0.90_rc | All | All | All |
| Application | Mplayer | Mplayer | 0.90_rc4 | All | All | All |
| Application | Mplayer | Mplayer | 0.91 | All | All | All |
| Application | Mplayer | Mplayer | 0.92 | All | All | All |
| Application | Mplayer | Mplayer | 0.92.1 | All | All | All |
| Application | Mplayer | Mplayer | 0.92_cvs | All | All | All |
| Application | Mplayer | Mplayer | 1.0_pre1 | All | All | All |
| Application | Mplayer | Mplayer | 1.0_pre2 | All | All | All |
| Application | Mplayer | Mplayer | 1.0_pre3 | All | All | All |
| Application | Mplayer | Mplayer | 1.0_pre3try2 | All | All | All |
| Application | Mplayer | Mplayer | 1.0_pre4 | All | All | All |
| Application | Mplayer | Mplayer | 1.0_pre5 | All | All | All |
| Application | Mplayer | Mplayer | 1.0_pre5try1 | All | All | All |
| Application | Mplayer | Mplayer | 1.0_pre5try2 | All | All | All |
| Application | Mplayer | Mplayer | head_cvs | All | All | All |
| Application | Xine | Xine | 0.9.13 | All | All | All |
| Application | Xine | Xine | 0.9.18 | All | All | All |
| Application | Xine | Xine | 0.9.8 | All | All | All |
| Application | Xine | Xine | 1_alpha | All | All | All |
| Application | Xine | Xine | 1_beta1 | All | All | All |
| Application | Xine | Xine | 1_beta10 | All | All | All |
| Application | Xine | Xine | 1_beta11 | All | All | All |
| Application | Xine | Xine | 1_beta12 | All | All | All |
| Application | Xine | Xine | 1_beta2 | All | All | All |
| Application | Xine | Xine | 1_beta3 | All | All | All |
| Application | Xine | Xine | 1_beta4 | All | All | All |
| Application | Xine | Xine | 1_beta5 | All | All | All |
| Application | Xine | Xine | 1_beta6 | All | All | All |
| Application | Xine | Xine | 1_beta7 | All | All | All |
| Application | Xine | Xine | 1_beta8 | All | All | All |
| Application | Xine | Xine | 1_beta9 | All | All | All |
| Application | Xine | Xine | 1_rc0 | All | All | All |
| Application | Xine | Xine | 1_rc0a | All | All | All |
| Application | Xine | Xine | 1_rc1 | All | All | All |
| Application | Xine | Xine | 1_rc2 | All | All | All |
| Application | Xine | Xine | 1_rc3 | All | All | All |
| Application | Xine | Xine | 1_rc3a | All | All | All |
| Application | Xine | Xine | 1_rc3b | All | All | All |
| Application | Xine | Xine | 1_rc4 | All | All | All |
| Application | Xine | Xine | 1_rc5 | All | All | All |
| Application | Xine | Xine | 1_rc6 | All | All | All |
| Application | Xine | Xine | 1_rc6a | All | All | All |
| Application | Xine | Xine | 1_rc7 | All | All | All |
| Application | Xine | Xine | 1_rc8 | All | All | All |
| Application | Xine | Xine-lib | 0.9.13 | All | All | All |
| Application | Xine | Xine-lib | 0.9.8 | All | All | All |
| Application | Xine | Xine-lib | 0.99 | All | All | All |
| Application | Xine | Xine-lib | 1_alpha | All | All | All |
| Application | Xine | Xine-lib | 1_beta1 | All | All | All |
| Application | Xine | Xine-lib | 1_beta10 | All | All | All |
| Application | Xine | Xine-lib | 1_beta11 | All | All | All |
| Application | Xine | Xine-lib | 1_beta12 | All | All | All |
| Application | Xine | Xine-lib | 1_beta2 | All | All | All |
| Application | Xine | Xine-lib | 1_beta3 | All | All | All |
| Application | Xine | Xine-lib | 1_beta4 | All | All | All |
| Application | Xine | Xine-lib | 1_beta5 | All | All | All |
| Application | Xine | Xine-lib | 1_beta6 | All | All | All |
| Application | Xine | Xine-lib | 1_beta7 | All | All | All |
| Application | Xine | Xine-lib | 1_beta8 | All | All | All |
| Application | Xine | Xine-lib | 1_beta9 | All | All | All |
| Application | Xine | Xine-lib | 1_rc0 | All | All | All |
| Application | Xine | Xine-lib | 1_rc1 | All | All | All |
| Application | Xine | Xine-lib | 1_rc2 | All | All | All |
| Application | Xine | Xine-lib | 1_rc3 | All | All | All |
| Application | Xine | Xine-lib | 1_rc3a | All | All | All |
| Application | Xine | Xine-lib | 1_rc3b | All | All | All |
| Application | Xine | Xine-lib | 1_rc3c | All | All | All |
| Application | Xine | Xine-lib | 1_rc4 | All | All | All |
| Application | Xine | Xine-lib | 1_rc5 | All | All | All |
| Application | Xine | Xine-lib | 1_rc6 | All | All | All |
| Application | Xine | Xine-lib | 1_rc6a | All | All | All |
| Application | Xine | Xine-lib | 1_rc7 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.mplayerhq.hu/MPlayer/patches/pnm_fix_20041215.diff | af854a3a-2127-422b-91ae-364da2661108 | www.mplayerhq.hu | |
| Advisories - Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SourceForge.net CVS Repository - diff - cvs: xine/xine-lib/src/input/pnm.c | af854a3a-2127-422b-91ae-364da2661108 | cvs.sourceforge.net | |
| iDEFENSE | af854a3a-2127-422b-91ae-364da2661108 | www.idefense.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.