Back
CVE-2004-1188
The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values, a different vulnerability than CVE-2004-1187.
Published: Jan 10, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (78)
| Vendor | Product | Version |
|---|---|---|
| mplayer | mplayer | 0.90 |
| mplayer | mplayer | 0.90_pre |
| mplayer | mplayer | 0.90_rc |
| mplayer | mplayer | 0.90_rc4 |
| mplayer | mplayer | 0.91 |
| mplayer | mplayer | 0.92 |
| mplayer | mplayer | 0.92.1 |
| mplayer | mplayer | 0.92_cvs |
| mplayer | mplayer | 1.0_pre1 |
| mplayer | mplayer | 1.0_pre2 |
| mplayer | mplayer | 1.0_pre3 |
| mplayer | mplayer | 1.0_pre3try2 |
| mplayer | mplayer | 1.0_pre4 |
| mplayer | mplayer | 1.0_pre5 |
| mplayer | mplayer | 1.0_pre5try1 |
| mplayer | mplayer | 1.0_pre5try2 |
| mplayer | mplayer | head_cvs |
| xine | xine | 0.9.8 |
| xine | xine | 0.9.13 |
| xine | xine | 0.9.18 |
…and 58 more
GitHub Security Advisory GHSA-4x57-68g7-9v3f
The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that...
References (10)
- http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/pnm.c?r1=1.20&r2=1.21
- http://www.idefense.com/application/poi/display?id=177&type=vulnerabilities Patch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:011
- http://www.mplayerhq.hu/MPlayer/patches/pnm_fix_20041215.diff
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18638
- http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/pnm.c?r1=1.20&r2=1.21
- http://www.idefense.com/application/poi/display?id=177&type=vulnerabilities Patch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:011
- http://www.mplayerhq.hu/MPlayer/patches/pnm_fix_20041215.diff
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18638
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
1.97%
Top 21% most likely to be exploited
Threat Score
40.6 / 100
Data Sources
NVD
EPSS
GitHub