CVE-2011-3625

mplayer2 - Stack-based Buffer Overflow in SAMI Subtitle Parser

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2011-3625. PoCs published by Metasploit, Jacques Louw, juan vazquez, including Metasploit module exploits/windows/fileformat/mplayer_sami_bof.

AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in MPlayer's handling of SAMI subtitle files. It generates a malicious .smi file that triggers the vulnerability when loaded, leading to arbitrary code execution.

Description

Stack-based buffer overflow in the sub_read_line_sami function in subreader.c in MPlayer, as used in SMPlayer 0.6.9, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a SAMI subtitle file.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/18954

This Metasploit module exploits a stack-based buffer overflow in MPlayer's handling of SAMI subtitle files. It generates a malicious .smi file that triggers the vulnerability when loaded, leading to arbitrary code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: MPlayer SVN versions before 33471 (specifically SMPlayer 0.6.8 with mplayer.exe Sherpya-SVN-r29355-4.5.0)
No auth needed
Prerequisites: Victim must open a movie file and load the malicious SAMI subtitle file, either via GUI or command line with the '-sub' option.
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Jacques Louw, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/mplayer_sami_bof.rb

This Metasploit module exploits a stack-based buffer overflow in MPlayer's handling of SAMI subtitle files (CVE-2011-3625). It targets SMPlayer 0.6.8 with a vulnerable MPlayer version, using a crafted .smi file to achieve remote code execution via a JMP ESP technique.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: MPlayer SVN before 33471 (via SMPlayer 0.6.8)
No auth needed
Prerequisites: Victim must open a movie file and load the malicious .smi subtitle file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/10/18/12
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/55486
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201310-13.xml

Scores

EPSS 0.2410
EPSS Percentile 97.6%

Details

CWE
CWE-119
Status published
Products (2)
mplayer2/mplayer2
ricardo_villalba/smplayer 0.6.9
Published Jun 11, 2014
Tracked Since Feb 18, 2026