CVE-2008-1768: Buffer Overflow
Published Apr 24, 2008
·Updated
Multiple integer overflows in VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via the (1) MP4 demuxer, (2) Real demuxer, and (3) Cinepak codec, which triggers a buffer overflow.
Affected Software
60 affected components
Videolan VLC=0.8.0
Videolan VLC=0.2.92
Videolan VLC=0.8.5
Videolan VLC=0.2.80
Videolan VLC=0.4.4
Videolan VLC=0.7.0
Videolan VLC=0.2.71
Videolan VLC=0.4.6
Videolan VLC=0.2.61
Videolan VLC=0.3.1
Videolan VLC=0.1.99
Videolan VLC=0.1.99c
Videolan VLC=0.8.4
Videolan VLC=0.2.81
Videolan VLC=0.8.6b
Videolan VLC=0.4.2
Videolan VLC=0.5.3
Videolan VLC=0.6.0
Videolan VLC=0.8.6c
Videolan VLC=0.7.1
Videolan VLC=0.1.99a
Videolan VLC=0.2.0
Videolan VLC=0.4.0
Videolan VLC=0.1.99h
Videolan VLC=0.4.5
Videolan VLC=0.6.1
Videolan VLC=0.1.99g
Videolan VLC=0.1.99i
Videolan VLC=0.6.2
Videolan VLC=0.5.2
Videolan VLC=0.4.1
Videolan VLC=0.8.6
Videolan VLC=0.1.99d
Videolan VLC=0.8.1337
Videolan VLC=0.8.1
Videolan VLC=0.2.62
Videolan VLC=0.8.6d
Videolan VLC=0.4.3_ac3
Videolan VLC=0.2.70
Videolan VLC=0.2.60
Videolan VLC=0.2.63
Videolan VLC=0.2.90
Videolan VLC=0.5.0
Videolan VLC=0.1.99f
Videolan VLC=0.8.6e
Videolan VLC=0.5.1
Videolan VLC=0.4.3
Videolan VLC=0.7.2
Videolan VLC=0.2.91
Videolan VLC=0.1.99e
Videolan VLC=0.2.50
Videolan VLC=0.1.99b
Videolan VLC=0.8.2
Videolan VLC=0.8.4a
Videolan VLC=0.2.72
Videolan VLC=0.3.0
Videolan VLC=0.2.82
Videolan VLC=0.2.73
Videolan VLC=0.8.6a
Videolan VLC=0.2.83
Event History
Apr 24, 2008
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1768?
CVE-2008-1768 is classified as a vulnerability that allowed remote attackers to cause a denial of service through integer overflows in VLC.
2
How do I fix CVE-2008-1768?
To fix CVE-2008-1768, users should upgrade to VLC version 0.8.6f or later, which addresses the integer overflow vulnerabilities.
3
Which versions of VLC are affected by CVE-2008-1768?
CVE-2008-1768 affects multiple versions of VLC including 0.2.0 through 0.8.6e.
4
What types of codecs are involved in the CVE-2008-1768 vulnerability?
The CVE-2008-1768 vulnerability involves the MP4 demuxer, Real demuxer, and Cinepak codec.
5
Can CVE-2008-1768 lead to a crash of VLC?
Yes, CVE-2008-1768 can result in VLC crashing due to buffer overflow caused by integer overflows.