First published: Tue Feb 26 2008(Updated: )
The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote attackers to overwrite arbitrary memory and execute arbitrary code via a malformed MP4 file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Miro | <=1.1 | |
VideoLAN VLC media player | <=0.8.6d |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-0984 is considered high due to its potential to allow remote code execution.
To fix CVE-2008-0984, update VLC media player to version 0.8.6e or later and Miro Player to version 1.1 or later.
CVE-2008-0984 affects VLC media player versions 0.8.6d and earlier, as well as Miro Player versions 1.1 and earlier.
CVE-2008-0984 allows remote attackers to overwrite arbitrary memory and execute arbitrary code through a malformed MP4 file.
The best workaround for CVE-2008-0984 is to avoid opening untrusted MP4 files until the software is updated.