Lucene search

K
cveMitreCVE-2008-5036
HistoryNov 10, 2008 - 10:18 p.m.

CVE-2008-5036

2008-11-1022:18:34
CWE-119
mitre
web.nvd.nist.gov
37
cve-2008-5036
vlc media player
buffer overflow
user-assisted
arbitrary code
realtext
subtitle file
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.97

Percentile

99.8%

Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execute arbitrary code via an an invalid RealText (rt) subtitle file, related to the ParseRealText function in modules/demux/subtitle.c. NOTE: this issue was SPLIT from CVE-2008-5032 on 20081110.

Affected configurations

Nvd
Node
videolanvlc_media_playerMatch0.9
OR
videolanvlc_media_playerMatch0.9.0
OR
videolanvlc_media_playerMatch0.9.1
OR
videolanvlc_media_playerMatch0.9.2
OR
videolanvlc_media_playerMatch0.9.3
OR
videolanvlc_media_playerMatch0.9.4
OR
videolanvlc_media_playerMatch0.9.5
VendorProductVersionCPE
videolanvlc_media_player0.9.0cpe:/a:videolan:vlc_media_player:0.9.0:::
videolanvlc_media_player0.9.2cpe:/a:videolan:vlc_media_player:0.9.2:::
videolanvlc_media_player0.9.4cpe:/a:videolan:vlc_media_player:0.9.4:::
videolanvlc_media_player0.9.3cpe:/a:videolan:vlc_media_player:0.9.3:::
videolanvlc_media_player0.9cpe:/a:videolan:vlc_media_player:0.9:::
videolanvlc_media_player0.9.5cpe:/a:videolan:vlc_media_player:0.9.5:::
videolanvlc_media_player0.9.1cpe:/a:videolan:vlc_media_player:0.9.1:::

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.97

Percentile

99.8%