Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-5276
HistoryDec 03, 2008 - 12:00 a.m.

CVE-2008-5276

2008-12-0300:00:00
ubuntu.com
ubuntu.com
16

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.301

Percentile

97.0%

Integer overflow in the ReadRealIndex function in real.c in the Real
demuxer plugin in VideoLAN VLC media player 0.9.0 through 0.9.7 allows
remote attackers to execute arbitrary code via a malformed RealMedia (.rm)
file that triggers a heap-based buffer overflow.

OSVersionArchitecturePackageVersionFilename
ubuntu8.10noarchvlc< 0.9.4-1ubuntu3.2UNKNOWN

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.301

Percentile

97.0%