Lucene search

K
cveMitreCVE-2008-5276
HistoryDec 03, 2008 - 5:30 p.m.

CVE-2008-5276

2008-12-0317:30:00
CWE-189
mitre
web.nvd.nist.gov
34
cve
2008
5276
integer overflow
readrealindex function
videolan
vlc media player
realmedia
buffer overflow

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.301

Percentile

97.0%

Integer overflow in the ReadRealIndex function in real.c in the Real demuxer plugin in VideoLAN VLC media player 0.9.0 through 0.9.7 allows remote attackers to execute arbitrary code via a malformed RealMedia (.rm) file that triggers a heap-based buffer overflow.

Affected configurations

Nvd
Node
videolanvlc_media_playerMatch0.9.0
OR
videolanvlc_media_playerMatch0.9.1
OR
videolanvlc_media_playerMatch0.9.2
OR
videolanvlc_media_playerMatch0.9.3
OR
videolanvlc_media_playerMatch0.9.4
OR
videolanvlc_media_playerMatch0.9.5
OR
videolanvlc_media_playerMatch0.9.6
OR
videolanvlc_media_playerMatch0.9.7
OR
videolanvlc_media_playerMatch0.9.8
VendorProductVersionCPE
videolanvlc_media_player0.9.0cpe:2.3:a:videolan:vlc_media_player:0.9.0:*:*:*:*:*:*:*
videolanvlc_media_player0.9.1cpe:2.3:a:videolan:vlc_media_player:0.9.1:*:*:*:*:*:*:*
videolanvlc_media_player0.9.2cpe:2.3:a:videolan:vlc_media_player:0.9.2:*:*:*:*:*:*:*
videolanvlc_media_player0.9.3cpe:2.3:a:videolan:vlc_media_player:0.9.3:*:*:*:*:*:*:*
videolanvlc_media_player0.9.4cpe:2.3:a:videolan:vlc_media_player:0.9.4:*:*:*:*:*:*:*
videolanvlc_media_player0.9.5cpe:2.3:a:videolan:vlc_media_player:0.9.5:*:*:*:*:*:*:*
videolanvlc_media_player0.9.6cpe:2.3:a:videolan:vlc_media_player:0.9.6:*:*:*:*:*:*:*
videolanvlc_media_player0.9.7cpe:2.3:a:videolan:vlc_media_player:0.9.7:*:*:*:*:*:*:*
videolanvlc_media_player0.9.8cpe:2.3:a:videolan:vlc_media_player:0.9.8:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.301

Percentile

97.0%