CVE-2008-1558
MPlayer - Remote Code Execution via Large streamid SDP Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1558. PoCs published by Guido Landi.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in MPlayer (CVE-2008-1558) by crafting a malicious RTSP response with an overly large stream ID, leading to arbitrary memory overwrite and potential remote code execution.
Description
Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote attackers to overwrite memory and execute arbitrary code via a large streamid SDP parameter. NOTE: this issue has been referred to as an integer overflow.
Exploits (1)
This exploit targets a buffer overflow vulnerability in MPlayer (CVE-2008-1558) by crafting a malicious RTSP response with an overly large stream ID, leading to arbitrary memory overwrite and potential remote code execution.