[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-4558Date: (C)2008-10-14   (M)2023-12-22


Array index error in VLC media player 0.9.2 allows remote attackers to overwrite arbitrary memory and execute arbitrary code via an XSPF playlist file with a negative identifier tag, which passes a signed comparison.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.8
Exploit Score: 8.6
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
http://www.securityfocus.com/archive/1/497354/100/0/threaded
BID-31758
SECUNIA-32267
EXPLOIT-DB-6756
ADV-2008-2826
http://www.coresecurity.com/content/vlc-xspf-memory-corruption
oval:org.mitre.oval:def:14726
vlc-parsetracknode-code-execution(45869)

CPE    1
cpe:/a:videolan:vlc_media_player:0.9.2
CWE    1
CWE-399
OVAL    1
oval:org.secpod.oval:def:16860

© SecPod Technologies