PT-2008-1141 · Videolan · Vlc Media Player
Publicado
2008-11-14
·
Atualizado
2018-10-11
·
CVE-2008-5276
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VideoLAN VLC media player versions 0.9.0 through 0.9.7
Description
The issue is caused by an integer overflow in the ReadRealIndex function in the Real demuxer plugin, which can trigger a heap-based buffer overflow. This allows remote attackers to execute arbitrary code via a malformed RealMedia (.rm) file.
Recommendations
For versions 0.9.0 through 0.9.7, update to a version that contains a fix for this issue to prevent exploitation. As a temporary workaround, consider avoiding the use of the Real demuxer plugin or restricting access to .rm files until a patch is available.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Vlc Media Player