CVE Vulnerabilities

CVE-2008-2147

Published: May 12, 2008 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

Untrusted search path vulnerability in VideoLAN VLC before 0.9.0 allows local users to execute arbitrary code via a malicious library under the modules/ or plugins/ subdirectories of the current working directory.

Affected Software

Name Vendor Start Version End Version
Vlc Videolan * 0.8.6 (including)
Vlc Videolan 0.4.6 (including) 0.4.6 (including)
Vlc Videolan 0.5.0 (including) 0.5.0 (including)
Vlc Videolan 0.5.1 (including) 0.5.1 (including)
Vlc Videolan 0.5.1a (including) 0.5.1a (including)
Vlc Videolan 0.5.2 (including) 0.5.2 (including)
Vlc Videolan 0.5.3 (including) 0.5.3 (including)
Vlc Videolan 0.6.0 (including) 0.6.0 (including)
Vlc Videolan 0.6.1 (including) 0.6.1 (including)
Vlc Videolan 0.6.2 (including) 0.6.2 (including)
Vlc Videolan 0.7.0 (including) 0.7.0 (including)
Vlc Videolan 0.7.1 (including) 0.7.1 (including)
Vlc Videolan 0.7.2 (including) 0.7.2 (including)
Vlc Videolan 0.8.0 (including) 0.8.0 (including)
Vlc Videolan 0.8.1 (including) 0.8.1 (including)
Vlc Videolan 0.8.2 (including) 0.8.2 (including)
Vlc Videolan 0.8.4 (including) 0.8.4 (including)
Vlc Videolan 0.8.4a (including) 0.8.4a (including)
Vlc Videolan 0.8.5 (including) 0.8.5 (including)
Vlc Videolan 0.8.6a (including) 0.8.6a (including)
Vlc Videolan 0.8.6b (including) 0.8.6b (including)
Vlc Videolan 0.8.6c (including) 0.8.6c (including)
Vlc Videolan 0.8.6d (including) 0.8.6d (including)
Vlc Videolan 0.8.6e (including) 0.8.6e (including)
Vlc Ubuntu dapper *
Vlc Ubuntu devel *
Vlc Ubuntu feisty *
Vlc Ubuntu gutsy *
Vlc Ubuntu hardy *
Vlc Ubuntu intrepid *
Vlc Ubuntu jaunty *
Vlc Ubuntu karmic *
Vlc Ubuntu upstream *

References