CVE-2011-3625

NameCVE-2011-3625
DescriptionStack-based buffer overflow in the sub_read_line_sami function in subreader.c in MPlayer, as used in SMPlayer 0.6.9, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a SAMI subtitle file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs645987, 646937

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mplayer (PTS)stretch2:1.3.0-6fixed
buster (security), buster, buster (lts)2:1.3.0-8+deb10u1fixed
bullseye2:1.4+ds1-1+deb11u1fixed
bookworm2:1.5+svn38408-1fixed
sid2:1.5+svn38638-3fixed
mplayer2 (PTS)jessie2.0-728-g2c378c7-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mplayersourcesqueeze(not affected)
mplayersource(unstable)2:1.0~rc4.dfsg1+svn33713-2645987
mplayer2source(unstable)2.0-134-g84d8671-9646937

Notes

[squeeze] - mplayer <not-affected> (Malformed SMI file correctly rejected, possibly introduced by later changes)

Search for package or bug name: Reporting problems