PT-2008-5092 · Endless Os · Eo-Video

J0Rgan

·

Published

2008-08-20

·

Updated

2017-09-29

·

CVE-2008-3733

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions eo-video version 1.36
Description The issue is a stack-based buffer overflow that allows remote attackers to cause a denial of service, resulting in an application crash, or execute arbitrary code. This is achieved through a .eop file, also known as a playlist file, which contains a ProjectElement element with a long Name element.
Recommendations For eo-video version 1.36, update to a version that contains a fix for this issue, as using a .eop file with a long Name element in the ProjectElement can lead to arbitrary code execution or denial of service.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3733

Affected Products

Eo-Video