Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-3794
HistoryAug 26, 2008 - 12:00 a.m.

CVE-2008-3794

2008-08-2600:00:00
ubuntu.com
ubuntu.com
17

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.152

Percentile

95.9%

Integer signedness error in the mms_ReceiveCommand function in
modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote
attackers to execute arbitrary code via a crafted mmst link with a negative
size value, which bypasses a size check and triggers an integer overflow
followed by a heap-based buffer overflow.

Bugs

Notes

Author Note
mdeslaur PoC: http://www.milw0rm.com/exploits/6293
OSVersionArchitecturePackageVersionFilename
ubuntu8.04noarchvlc< 0.8.6.release.e+x264svn20071224+faad2.6.1-0ubuntu3.2UNKNOWN

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.152

Percentile

95.9%