The remote host is missing an update to mplayer announced via advisory MDKSA-2005:230.
Simon Kilvington discovered a vulnerability in FFmpeg libavcodec, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a user's system.
The vulnerability is caused due to a boundary error in the avcodec_default_get_buffer() function of utils.c in libavcodec. This can be exploited to cause a heap-based buffer overflow when a specially-crafted 1x1 .png file containing a palette is read.
Mplayer is built with a private copy of ffmpeg containing this same code.
The updated packages have been patched to prevent this problem.
Affected: 2006.0, Corporate 3.0
Solution: To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.