Multiple buffer overflows in asf_http_request of MPlayer before 0.92 allows remote attackers to execute arbitrary code via an ASX header with a long hostname.
http://www.mplayerhq.hu/homepage/design6/news.html
http://marc.info/?l=bugtraq&m=106485005213109&w=2
http://marc.info/?l=bugtraq&m=106460912721618&w=2
http://marc.info/?l=bugtraq&m=106454257221455&w=2
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000760