CVE Vulnerabilities

CVE-2008-4686

Published: Oct 22, 2008 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote attackers to execute arbitrary code via a crafted .ty file, a different vulnerability than CVE-2008-4654.

Affected Software

Name Vendor Start Version End Version
Vlc_media_player Videolan 0.9.0 (including) 0.9.0 (including)
Vlc_media_player Videolan 0.9.1 (including) 0.9.1 (including)
Vlc_media_player Videolan 0.9.2 (including) 0.9.2 (including)
Vlc_media_player Videolan 0.9.3 (including) 0.9.3 (including)
Vlc_media_player Videolan 0.9.4 (including) 0.9.4 (including)

References