Several vulnerabilities have been discovered in mplayer, which could
allow remote attackers to execute arbitrary code via a malformed
TwinVQ file (CVE-2008-5616), and in ffmpeg, as used by mplayer,
related to the execution of DTS generation code (CVE-2008-4866)
and incorrect handling of DCA_MAX_FRAME_SIZE value (CVE-2008-4867).
The updated packages have been patched to prevent this.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2008-4866
http://cve.mitre.org/cgi-bin/cvename.cg ... -2008-4867
http://cve.mitre.org/cgi-bin/cvename.cg ... -2008-5616
_______________________________________________________________________