Vulnerability Name: | CVE-2007-3468 (CCN-35411) | ||||||||||||||||
Assigned: | 2007-06-21 | ||||||||||||||||
Published: | 2007-06-21 | ||||||||||||||||
Updated: | 2018-10-16 | ||||||||||||||||
Summary: | input.c in VideoLAN VLC Media Player before 0.8.6c allows remote attackers to cause a denial of service (crash) via a crafted WAV file that causes an uninitialized i_nb_resamplers variable to be used. | ||||||||||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C) 5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Jun 21 2007 - 13:28:11 CDT VLC 0.8.6b format string vulnerability & integer overflow Source: MITRE Type: CNA CVE-2007-3468 Source: OSVDB Type: UNKNOWN 38992 Source: SECUNIA Type: UNKNOWN 25980 Source: DEBIAN Type: UNKNOWN DSA-1332 Source: DEBIAN Type: DSA-1332 vlc -- several vulnerabilities Source: MISC Type: Patch http://www.isecpartners.com/advisories/2007-001-vlc.txt Source: CCN Type: OSVDB ID: 38992 VLC Media Player input.c Crafted WAV Remote DoS Source: BUGTRAQ Type: UNKNOWN 20070621 VLC 0.8.6b format string vulnerability & integer overflow Source: CCN Type: VideoLAN Web site VLC media player - Overview Source: XF Type: UNKNOWN vlcmediaplayer-input-dos(35411) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:14744 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |