CVE-2007-0017: Medium severity Videolan VLC Media Player vulnerability
Multiple format string vulnerabilities in (1) the cdiologhandler function in modules/access/cdda/access.c in the CDDA (libcddaplugin) plugin, and the (2) cdiologhandler and (3) vcdloghandler functions in modules/access/vcdx/access.c in the VCDX (libvcdxplugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an invalid URI, as demonstrated by a udp://-- URI in an M3U file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0017?
CVE-2007-0017 has a moderate severity level due to potential exploitation leading to information disclosure or application crashes.
How do I fix CVE-2007-0017?
To mitigate CVE-2007-0017, it is recommended to update the VLC media player to a version that is not affected by this vulnerability.
Which versions of VLC media player are affected by CVE-2007-0017?
CVE-2007-0017 affects VLC media player versions 0.7.0 through 0.8.6, including various subversions.
What kind of vulnerabilities are described in CVE-2007-0017?
CVE-2007-0017 describes multiple format string vulnerabilities in the CDDA and VCDX plugins of VLC media player.
Can CVE-2007-0017 lead to remote code execution?
CVE-2007-0017 does not specifically lead to remote code execution, but it can allow attackers to potentially disrupt service or disclose information.