CVE-2007-6682: High severity Videolan VLC vulnerability
Published Jan 17, 2008
·Updated
Format string vulnerability in the httpdFileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via format string specifiers in the Connection parameter.
Affected Software
1 affected component
Videolan VLC<=0.8.6d
Event History
Jan 17, 2008
CVE Published
01:00 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6682?
CVE-2007-6682 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2007-6682?
To fix CVE-2007-6682, upgrade VLC media player to version 0.8.6e or later.
3
Who is affected by CVE-2007-6682?
CVE-2007-6682 affects users of VideoLAN VLC version 0.8.6d and earlier.
4
What type of vulnerability is CVE-2007-6682?
CVE-2007-6682 is a format string vulnerability that can lead to arbitrary code execution.
5
Can CVE-2007-6682 be exploited remotely?
Yes, CVE-2007-6682 can be exploited remotely through malicious format string specifiers.