CVE-2008-3794: Buffer Overflow
Published Aug 26, 2008
·Updated
Integer signedness error in the mmsReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote attackers to execute arbitrary code via a crafted mmst link with a negative size value, which bypasses a size check and triggers an integer overflow followed by a heap-based buffer overflow.
Affected Software
1 affected component
Videolan VLC Media Player=0.8.6i
Event History
Aug 26, 2008
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3794?
CVE-2008-3794 is considered critical due to the potential for remote code execution.
2
How do I fix CVE-2008-3794?
To fix CVE-2008-3794, update VLC Media Player to a version later than 0.8.6i.
3
What versions of VLC Media Player are affected by CVE-2008-3794?
VLC Media Player version 0.8.6i is vulnerable to CVE-2008-3794.
4
How does CVE-2008-3794 exploit the VLC Media Player?
CVE-2008-3794 exploits an integer signedness error that allows attackers to execute arbitrary code via a crafted mmst link.
5
Can CVE-2008-3794 be exploited remotely?
Yes, CVE-2008-3794 can be exploited remotely by using a malicious mmst link.