CVE-2008-1489: Buffer Overflow
Integer overflow in the MP4ReadBoxrdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MP4 RDRF box that triggers a heap-based buffer overflow, a different vulnerability than CVE-2008-0984.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1489?
CVE-2008-1489 is considered to be of high severity due to its potential for causing denial of service and arbitrary code execution.
How do I fix CVE-2008-1489?
To fix CVE-2008-1489, upgrade VLC media player to a version newer than 0.8.6e which addresses this vulnerability.
Who is affected by CVE-2008-1489?
CVE-2008-1489 affects users of VLC media player version 0.8.6e.
What type of vulnerability is CVE-2008-1489?
CVE-2008-1489 is an integer overflow vulnerability that can lead to a heap-based buffer overflow.
Is CVE-2008-1489 a publicly known vulnerability?
Yes, CVE-2008-1489 is a publicly acknowledged vulnerability reported in 2008.