CVE Vulnerabilities

CVE-2008-2147

Published: May 12, 2008 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Untrusted search path vulnerability in VideoLAN VLC before 0.9.0 allows local users to execute arbitrary code via a malicious library under the modules/ or plugins/ subdirectories of the current working directory.

Affected Software

Name Vendor Start Version End Version
Vlc Videolan * 0.8.6 (including)
Vlc Videolan 0.4.6 (including) 0.4.6 (including)
Vlc Videolan 0.5.0 (including) 0.5.0 (including)
Vlc Videolan 0.5.1 (including) 0.5.1 (including)
Vlc Videolan 0.5.1a (including) 0.5.1a (including)
Vlc Videolan 0.5.2 (including) 0.5.2 (including)
Vlc Videolan 0.5.3 (including) 0.5.3 (including)
Vlc Videolan 0.6.0 (including) 0.6.0 (including)
Vlc Videolan 0.6.1 (including) 0.6.1 (including)
Vlc Videolan 0.6.2 (including) 0.6.2 (including)
Vlc Videolan 0.7.0 (including) 0.7.0 (including)
Vlc Videolan 0.7.1 (including) 0.7.1 (including)
Vlc Videolan 0.7.2 (including) 0.7.2 (including)
Vlc Videolan 0.8.0 (including) 0.8.0 (including)
Vlc Videolan 0.8.1 (including) 0.8.1 (including)
Vlc Videolan 0.8.2 (including) 0.8.2 (including)
Vlc Videolan 0.8.4 (including) 0.8.4 (including)
Vlc Videolan 0.8.4a (including) 0.8.4a (including)
Vlc Videolan 0.8.5 (including) 0.8.5 (including)
Vlc Videolan 0.8.6a (including) 0.8.6a (including)
Vlc Videolan 0.8.6b (including) 0.8.6b (including)
Vlc Videolan 0.8.6c (including) 0.8.6c (including)
Vlc Videolan 0.8.6d (including) 0.8.6d (including)
Vlc Videolan 0.8.6e (including) 0.8.6e (including)

References