CVE-2007-3467: Integer Overflow
Published Jun 27, 2007
·Updated
Integer overflow in the statusUpdate function in stats.c VideoLAN VLC Media Player before 0.8.6c allows remote attackers to cause a denial of service (crash) via a WAV file with a large sample rate.
Affected Software
1 affected component
Videolan VLC Media Player<=0.8.6b
Remediation
Patch Available
Event History
Jun 27, 2007
CVE Published
10:30 PM
Jun 28, 2007
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3467?
CVE-2007-3467 has a severity level of medium due to its potential for causing a denial of service.
2
How do I fix CVE-2007-3467?
To fix CVE-2007-3467, upgrade your VideoLAN VLC Media Player to version 0.8.6c or later.
3
What software versions are affected by CVE-2007-3467?
CVE-2007-3467 affects VideoLAN VLC Media Player versions prior to 0.8.6c.
4
What type of attack does CVE-2007-3467 enable?
CVE-2007-3467 enables remote attackers to execute a denial of service attack by crashing the media player.
5
What files are particularly dangerous in relation to CVE-2007-3467?
WAV files with large sample rates are particularly dangerous concerning CVE-2007-3467.