CVE-2011-10008 describes a stack-based buffer overflow in MPlayer Lite r33064, specifically when processing M3U playlist files containing overly long HTTP URL entries. This vulnerability, rated as High severity (CVSS 8.6), allows an unauthenticated attacker to achieve arbitrary code execution with user privileges, typically through user interaction like drag-and-drop of a crafted .m3u file. Exploitation is facilitated by publicly available Metasploit modules that demonstrate SEH overwrite and DEP bypass techniques. While not actively exploited in the wild, the vulnerability has significant community discussion and a high FAUCET Risk Score, indicating its potential for abuse.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| MPlayer Project | MPlayer Lite | r33064CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.