Stack-based buffer overflow in libmms, as used by (a) MiMMS 0.0.9 and (b) xine-lib 1.1.0 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via the (1) sendcommand, (2) stringutf16, (3) getdata, and (4) getmedia_packet functions, and possibly other functions.