LWN.net Logo

vlc: multiple vulnerabilities

Package(s):vlc CVE #(s):CVE-2008-3732 CVE-2008-3794
Created:September 8, 2008 Updated:June 18, 2009
Description:

From the Gentoo advisory:

g_ reported the following vulnerabilities:

* An integer overflow leading to a heap-based buffer overflow in the Open() function in modules/demux/tta.c (CVE-2008-3732).

* A signedness error leading to a stack-based buffer overflow in the mms_ReceiveCommand() function in modules/access/mms/mmstu.c (CVE-2008-3794).

A remote attacker could entice a user to open a specially crafted file, possibly resulting in the remote execution of arbitrary code with the privileges of the user running the application.

Alerts:
Debian DSA-1819-1 2009-06-18
Gentoo 200809-06 2008-09-07

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds