CVE-2008-2147: Medium severity vlc for mobile vulnerability
Published May 12, 2008
·Updated
Untrusted search path vulnerability in VideoLAN VLC before 0.9.0 allows local users to execute arbitrary code via a malicious library under the modules/ or plugins/ subdirectories of the current working directory.
Affected Software
24 affected components
Videolan VLC=0.8.0
Videolan VLC=0.8.5
Videolan VLC=0.7.0
Videolan VLC=0.4.6
Videolan VLC=0.8.4
Videolan VLC=0.8.6b
Videolan VLC=0.5.3
Videolan VLC=0.6.0
Videolan VLC=0.8.6c
Videolan VLC=0.7.1
Videolan VLC=0.6.1
Videolan VLC=0.6.2
Videolan VLC=0.5.2
Videolan VLC=0.5.1a
Videolan VLC=0.8.1
Videolan VLC=0.8.6d
Videolan VLC=0.5.0
Videolan VLC=0.8.6e
Videolan VLC=0.5.1
Videolan VLC=0.7.2
Videolan VLC<=0.8.6
Videolan VLC=0.8.2
Videolan VLC=0.8.4a
Videolan VLC=0.8.6a
Event History
May 12, 2008
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2147?
CVE-2008-2147 is considered to be of medium severity due to the potential for arbitrary code execution.
2
How do I fix CVE-2008-2147?
To fix CVE-2008-2147, upgrade VLC to version 0.9.0 or later.
3
What versions of VLC are affected by CVE-2008-2147?
CVE-2008-2147 affects VLC versions prior to 0.9.0, including all 0.8.x and earlier versions.
4
Can CVE-2008-2147 be exploited remotely?
CVE-2008-2147 cannot be exploited remotely as it requires local access to the vulnerable system.
5
What are the potential consequences of exploiting CVE-2008-2147?
Exploiting CVE-2008-2147 could lead to arbitrary code execution, allowing attackers to compromise the affected system.