CVE-2008-1558
MPlayer 1.0 rc2 - RCE
Title source: llmDescription
Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote attackers to overwrite memory and execute arbitrary code via a large streamid SDP parameter. NOTE: this issue has been referred to as an integer overflow.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Guido Landi · perldoslinux
https://www.exploit-db.com/exploits/5307
References (10)
Scores
EPSS
0.2194
EPSS Percentile
95.8%
Details
CWE
CWE-189
Status
published
Products (1)
mplayer/mplayer
1.0_rc2
Published
Mar 31, 2008
Tracked Since
Feb 18, 2026