First published: Wed Oct 22 2008(Updated: )
Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote attackers to execute arbitrary code via a crafted .ty file, a different vulnerability than CVE-2008-4654.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VideoLAN VLC media player | =0.9.0 | |
VideoLAN VLC media player | =0.9.4 | |
VideoLAN VLC media player | =0.9.1 | |
VideoLAN VLC media player | =0.9.2 | |
VideoLAN VLC media player | =0.9.3 | |
VLC media player | =0.9.0 | |
VLC media player | =0.9.1 | |
VLC media player | =0.9.2 | |
VLC media player | =0.9.3 | |
VLC media player | =0.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4686 is classified as a critical vulnerability due to the potential for remote code execution.
To fix CVE-2008-4686, update to VLC media player version 0.9.5 or later where the vulnerability has been addressed.
VLC media player versions 0.9.0, 0.9.1, 0.9.2, 0.9.3, and 0.9.4 are affected by CVE-2008-4686.
CVE-2008-4686 can be exploited by remote attackers through the use of a crafted .ty file.
Yes, CVE-2008-4686 affects all platforms that run the vulnerable versions of VLC media player.