CVE-2008-3732: Buffer Overflow
Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TTA file, which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3732?
CVE-2008-3732 has a medium severity as it can cause a denial of service or potentially allow arbitrary code execution.
How do I fix CVE-2008-3732?
The fix for CVE-2008-3732 involves updating VLC Media Player to version 0.8.6j or later.
What types of attacks can CVE-2008-3732 facilitate?
CVE-2008-3732 can facilitate remote denial of service attacks and might allow attackers to execute arbitrary code.
Which versions of VLC Media Player are affected by CVE-2008-3732?
VLC Media Player version 0.8.6i is affected by CVE-2008-3732.
What should I do if I'm using VLC Media Player version 0.8.6i regarding CVE-2008-3732?
If using VLC Media Player version 0.8.6i, you should upgrade to a patched version to mitigate CVE-2008-3732.