First published: Mon Jul 07 2008(Updated: )
Integer overflow in the Open function in modules/demux/wav.c in VLC Media Player 0.8.6h on Windows allows remote attackers to execute arbitrary code via a large fmt chunk in a WAV file.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows NT | ||
VideoLAN VLC media player | =0.8.6h |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2430 is considered critical as it allows remote attackers to execute arbitrary code on affected systems.
To fix CVE-2008-2430, update VLC Media Player to version 0.8.6i or later.
CVE-2008-2430 affects VLC Media Player version 0.8.6h running on Windows.
CVE-2008-2430 is an integer overflow vulnerability that allows for remote code execution.
Yes, CVE-2008-2430 can be exploited remotely through specially crafted WAV files.