Several vulnerabilities have been discovered in mplayer, a movie player for Unix-like systems. The Common Vulnerabilities and Exposures project identifies the following problems:
It was discovered that watching a malformed 4X movie file could lead to the execution of arbitrary code.
It was discovered that multiple buffer overflows could lead to the execution of arbitrary code.
It was discovered that watching a malformed TwinVQ file could lead to the execution of arbitrary code.
For the oldstable distribution (etch), these problems have been fixed in version 1.0~rc1-12etch7.
For the stable distribution (lenny), mplayer links against ffmpeg-debian.
For the testing distribution (squeeze) and the unstable distribution (sid), mplayer links against ffmpeg-debian.
We recommend that you upgrade your mplayer packages.
MD5 checksums of the listed files are available in the original advisory.