CVE Vulnerabilities

CVE-2007-3316

Published: Jun 21, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple format string vulnerabilities in plugins in VideoLAN VLC Media Player before 0.8.6c allow remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in (1) an Ogg/Vorbis file, (2) an Ogg/Theora file, (3) a CDDB entry for a CD Digital Audio (CDDA) file, or (4) Service Announce Protocol (SAP) multicast packets.

Affected Software

NameVendorStart VersionEnd Version
Vlc_media_playerVideolan0.8.6a (including)0.8.6a (including)
Vlc_media_playerVideolan0.8.6b (including)0.8.6b (including)
VlcUbuntudapper*
VlcUbuntudevel*
VlcUbuntuedgy*
VlcUbuntufeisty*
VlcUbuntugutsy*
VlcUbuntuhardy*
VlcUbuntuintrepid*
VlcUbuntujaunty*
VlcUbuntukarmic*

References