PT-2008-1148 · Videolan · Vlc

Mai Xuan Cuong

·

Published

2008-04-17

·

Updated

2017-09-29

·

CVE-2008-1881

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions VLC version 0.8.6e
Description The issue is related to a stack-based buffer overflow in the ParseSSA function, located in modules/demux/subtitle.c. This allows remote attackers to execute arbitrary code via a long subtitle in an SSA file. The problem is due to an incomplete fix for a previous issue.
Recommendations For VLC version 0.8.6e, consider disabling the ParseSSA function as a temporary workaround until a patch is available. Restrict access to SSA files to minimize the risk of exploitation.

Exploit

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03969
CVE-2008-1881
DSA-1819-1
DTSA-125-1

Affected Products

Vlc