Lucene search

K
freebsdFreeBSDACF80AFA-C3EF-11DD-A721-0030843D3802
HistoryNov 30, 2008 - 12:00 a.m.

vlc -- arbitrary code execution in the RealMedia processor

2008-11-3000:00:00
vuxml.freebsd.org
12

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.301

Percentile

97.0%

Tobias Klein from TrapKit reports:

The VLC media player contains an integer overflow vulnerability
while parsing malformed RealMedia (.rm) files. The vulnerability
leads to a heap overflow that can be exploited by a (remote)
attacker to execute arbitrary code in the context of VLC media
player.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchvlc-devel< 0.9.8aUNKNOWN

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.301

Percentile

97.0%