First published: Wed Aug 20 2008(Updated: )
Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TTA file, which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VideoLAN VLC media player | =0.8.6i |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3732 has a medium severity as it can cause a denial of service or potentially allow arbitrary code execution.
The fix for CVE-2008-3732 involves updating VLC Media Player to version 0.8.6j or later.
CVE-2008-3732 can facilitate remote denial of service attacks and might allow attackers to execute arbitrary code.
VLC Media Player version 0.8.6i is affected by CVE-2008-3732.
If using VLC Media Player version 0.8.6i, you should upgrade to a patched version to mitigate CVE-2008-3732.