A format string vulnerability in mpv through 0.33.0 allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file.
{ "binaries": [ { "binary_name": "libmpv-dev", "binary_version": "0.14.0-1build1" }, { "binary_name": "libmpv1", "binary_version": "0.14.0-1build1" }, { "binary_name": "mpv", "binary_version": "0.14.0-1build1" } ] }
{ "binaries": [ { "binary_name": "libmpv-dev", "binary_version": "0.27.2-1ubuntu1" }, { "binary_name": "libmpv1", "binary_version": "0.27.2-1ubuntu1" }, { "binary_name": "mpv", "binary_version": "0.27.2-1ubuntu1" } ] }
{ "binaries": [ { "binary_name": "libmpv-dev", "binary_version": "0.32.0-1ubuntu1" }, { "binary_name": "libmpv1", "binary_version": "0.32.0-1ubuntu1" }, { "binary_name": "mpv", "binary_version": "0.32.0-1ubuntu1" } ] }
{ "binaries": [ { "binary_name": "libmpv-dev", "binary_version": "0.34.1-1ubuntu3" }, { "binary_name": "libmpv1", "binary_version": "0.34.1-1ubuntu3" }, { "binary_name": "mpv", "binary_version": "0.34.1-1ubuntu3" } ] }