Oval Definition:oval:org.mitre.oval:def:8254
Revision Date:2014-06-23Version:21
Title:DSA-1819 vlc -- several vulnerabilities
Description:Several vulnerabilities have been discovered in vlc, a multimedia player and streamer. The Common Vulnerabilities and Exposures project identifies the following problems: Drew Yao discovered that multiple integer overflows in the MP4 demuxer, Real demuxer and Cinepak codec can lead to the execution of arbitrary code. Drew Yao discovered that the Cinepak codec is prone to a memory corruption, which can be triggered by a crafted Cinepak file. Luigi Auriemma discovered that it is possible to execute arbitrary code via a long subtitle in an SSA file. It was discovered that vlc is prone to a search path vulnerability, which allows local users to perform privilege escalations. Alin Rad Pop discovered that it is possible to execute arbitrary code when opening a WAV file containing a large fmt chunk. Pinar Yanarda discovered that it is possible to execute arbitrary code when opening a crafted mmst link. Tobias Klein discovered that it is possible to execute arbitrary code when opening a crafted .ty file. Tobias Klein discovered that it is possible to execute arbitrary code when opening an invalid CUE image file with a crafted header.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2008-1768
CVE-2008-1769
CVE-2008-1881
CVE-2008-2147
CVE-2008-2430
CVE-2008-3794
CVE-2008-4686
CVE-2008-5032
DSA-1819
Platform(s):Debian GNU/Linux 4.0
Product(s):vlc
Definition Synopsis
  • Debian GNU/Linux 4.0 is installed.
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • wxvlc is earlier than 0.8.6-svn20061012.debian-5.1+etch3
  • OR vlc-plugin-alsa is earlier than 0.8.6-svn20061012.debian-5.1+etch3
  • OR vlc-plugin-arts is earlier than 0.8.6-svn20061012.debian-5.1+etch3
  • OR vlc is earlier than 0.8.6-svn20061012.debian-5.1+etch3
  • OR mozilla-plugin-vlc is earlier than 0.8.6-svn20061012.debian-5.1+etch3
  • OR vlc-plugin-ggi is earlier than 0.8.6-svn20061012.debian-5.1+etch3
  • OR vlc-plugin-esd is earlier than 0.8.6-svn20061012.debian-5.1+etch3
  • OR libvlc0-dev is earlier than 0.8.6-svn20061012.debian-5.1+etch3
  • OR libvlc0 is earlier than 0.8.6-svn20061012.debian-5.1+etch3
  • OR vlc-nox is earlier than 0.8.6-svn20061012.debian-5.1+etch3
  • OR vlc-plugin-sdl is earlier than 0.8.6-svn20061012.debian-5.1+etch3
  • OR Architecture dependent section
  • Installed architecture is i386
  • AND Packages section
  • vlc-plugin-glide is earlier than 0.8.6-svn20061012.debian-5.1+etch3
  • OR vlc-plugin-svgalib is earlier than 0.8.6-svn20061012.debian-5.1+etch3
  • BACK