CVE-2006-2200

NameCVE-2006-2200
DescriptionStack-based buffer overflow in libmms, as used by (a) MiMMS 0.0.9 and (b) xine-lib 1.1.0 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via the (1) send_command, (2) string_utf16, (3) get_data, and (4) get_media_packet functions, and possibly other functions.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs374577

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libmms (PTS)sid, trixie, buster, bookworm, bullseye0.6.4-3fixed
mimms (PTS)buster3.2.2-1.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libmmssource(unstable)0.2-7medium374577
mimmssource(unstable)2.0.0-1medium374577
xine-libsource(unstable)1.1.2-2unimportant374577

Notes

Not exploitable within xine, as alloced buffer are large enough

Search for package or bug name: Reporting problems