{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "low"
      },
      "package": {
        "ecosystem": "Debian:11",
        "name": "mplayer"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.0~rc3+svn20100502-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "low"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "mplayer"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.0~rc3+svn20100502-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "low"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "mplayer"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.0~rc3+svn20100502-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "low"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "mplayer"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.0~rc3+svn20100502-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "MPlayer, possibly 1.0rc1, allows remote attackers to cause a denial of service (SIGSEGV and application crash) via (1) a malformed MP3 file, as demonstrated by lol-mplayer.mp3; (2) a malformed Ogg Vorbis file, as demonstrated by lol-mplayer.ogg; (3) a malformed MPEG-1 file, as demonstrated by lol-mplayer.mpg; (4) a malformed MPEG-2 file, as demonstrated by lol-mplayer.m2v; (5) a malformed MPEG-4 AVI file, as demonstrated by lol-mplayer.avi; (6) a malformed FLAC file, as demonstrated by lol-mplayer.flac; (7) a malformed Ogg Theora file, as demonstrated by lol-mplayer.ogm; (8) a malformed WMV file, as demonstrated by lol-mplayer.wmv; or (9) a malformed AAC file, as demonstrated by lol-mplayer.aac.  NOTE: vector 5 might overlap CVE-2007-4938, and vector 6 might overlap CVE-2008-0486.",
  "id": "DEBIAN-CVE-2007-6718",
  "modified": "2026-04-28T19:49:40.368948598Z",
  "published": "2008-10-20T17:59:23.053Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2007-6718"
    }
  ],
  "upstream": [
    "CVE-2007-6718"
  ]
}