6.8
CVSSv2

CVE-2008-4558

Published: 15/10/2008 Updated: 11/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Array index error in VLC media player 0.9.2 allows remote malicious users to overwrite arbitrary memory and execute arbitrary code via an XSPF playlist file with a negative identifier tag, which passes a signed comparison.

Vulnerable Product Search on Vulmon Subscribe to Product

videolan vlc media player 0.9.2

Vendor Advisories

Debian Bug report logs - #502314 vlc: CVE-2008-4558 code execution via crafted xspf playlist file Package: vlc; Maintainer for vlc is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for vlc is src:vlc (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Wed, 15 Oct 2008 14: ...
Debian Bug report logs - #502314 vlc: CVE-2008-4558 code execution via crafted xspf playlist file Package: vlc; Maintainer for vlc is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for vlc is src:vlc (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Wed, 15 Oct 2008 14: ...

Exploits

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Core Security Technologies - CoreLabs Advisory wwwcoresecuritycom/corelabs/ VLC media player XSPF Memory Corruption 1 *Advisory Information* Title: VLC media player XSPF Memory Corruption Advisory ID: CORE-2008-1010 Advisory URL: wwwcoresecuritycom/conte ...