PT-2007-7482 · Videolan · Vlc Media Player

David Thiel

·

Published

1970-01-01

·

Updated

2018-10-16

·

CVE-2007-3468

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VLC Media Player version 0.8.6 and earlier
Description The issue allows remote attackers to cause a denial of service via a crafted WAV file. Multiple vulnerabilities in the VLC Media Player package may lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations For versions prior to 0.8.6, update to version 0.8.6c or later to resolve the issue. As a temporary workaround, consider avoiding the use of crafted WAV files until a patch is available. Restrict access to the vulnerable input.c file to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-01753
BDU:2015-01754
BDU:2015-01755
BDU:2015-01756
BDU:2015-01765
CVE-2007-3468
DSA-1332-1

Affected Products

Vlc Media Player