Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote attackers to execute arbitrary code via a crafted .ty file, a different vulnerability than CVE-2008-4654.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Vlc_media_player | Videolan | 0.9.0 (including) | 0.9.0 (including) |
| Vlc_media_player | Videolan | 0.9.1 (including) | 0.9.1 (including) |
| Vlc_media_player | Videolan | 0.9.2 (including) | 0.9.2 (including) |
| Vlc_media_player | Videolan | 0.9.3 (including) | 0.9.3 (including) |
| Vlc_media_player | Videolan | 0.9.4 (including) | 0.9.4 (including) |
| Vlc | Ubuntu | dapper | * |
| Vlc | Ubuntu | gutsy | * |
| Vlc | Ubuntu | intrepid | * |
| Vlc | Ubuntu | upstream | * |