A fix for this problem was committed to SVN on Sun Jan 20 2008 UTC as r25824.Users of affected MPlayer versions should download a patch for MPlayer 1.0rc2 or update to the latest version if they are using SVN.Please be kind to our server and use one of our many mirrors.A buffer overflow was found and reported by Adam Bozanich of Musecurity in the code used to extract album titles from CDDB server answers.If you have a file which does not play with MPlayer, please upload it so we can take a look.You can find instructions in the Bugreports section of the documentation.About a year ago, a couple of developers related to MPlayer took over the task of maintaining libdvdnav.The first release happened quietly on Sunday, October 28th 2007 and now it is time for another.

The Picsearch team makes extensive use of FFmpeg and provided feedback to FFmpeg in the form of thousands of files that either crash FFmpeg or use unsupported/unknown codecs.Please note that it is possible to overwrite entries in the CDDB database, so an attack can also be performed via a non-compromised server.At the time the buffer overflow was fixed there was no known exploit in the wild.The FFmpeg development team is putting this information to work in order to improve FFmpeg for everyone.We know that there are other organizations using FFmpeg on a large scale to process diverse input types.When parsing answers from the CDDB server, the album title is copied into a fixed-size buffer with insufficient size checks, which may cause a buffer overflow.A malicious database entry could trigger a buffer overflow in the program.SVN HEAD after r25824 (Sun Jan 20 2008 UTC) MPlayer 1.0rc2 security patches A buffer overflow was found and reported by Adam Bozanich of Musecurity in the code used to escape URL strings.The code used to skip over IPv6 addresses can be tricked into leaving a pointer to a temporary buffer with a non-NULL value; this causes the unescape code to reuse the buffer, and may lead to a buffer overflow if the old buffer is smaller than required.We suspect that Youtube uses our software, and we would like everyone to benefit from their work.One of our goals is to be able to play every video file.


