6.8
CVSSv2

CVE-2008-3794

Published: 26/08/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote malicious users to execute arbitrary code via a crafted mmst link with a negative size value, which bypasses a size check and triggers an integer overflow followed by a heap-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

videolan vlc media player 0.8.6i

Vendor Advisories

Debian Bug report logs - #496265 vlc: buffer overflow in mms handling Package: vlc; Maintainer for vlc is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for vlc is src:vlc (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Sun, 24 Aug 2008 00:21:01 UTC Severity: grave T ...
Several vulnerabilities have been discovered in vlc, a multimedia player and streamer The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-1768 Drew Yao discovered that multiple integer overflows in the MP4 demuxer, Real demuxer and Cinepak codec can lead to the execution of arbitrary code CVE-2008-1769 Dr ...

Exploits

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - Orange Bat advisory - Name : VLC 086i MMS Protocol Handling Class : Heap Overflow Published : 2008-08-24 Credit : g_ (g_ # orange-bat # com) - - Details - This can be exploited from remote User have to open mmst:// link poiting to server controlled by the attacker vlc\mod ...