CVE-2008-4686: Integer Overflow
Published Oct 22, 2008
·Updated
Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote attackers to execute arbitrary code via a crafted .ty file, a different vulnerability than CVE-2008-4654.
Affected Software
5 affected components
Videolan VLC Media Player=0.9.0
Videolan VLC Media Player=0.9.1
Videolan VLC Media Player=0.9.2
Videolan VLC Media Player=0.9.3
Videolan VLC Media Player=0.9.4
Event History
Oct 22, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4686?
CVE-2008-4686 is classified as a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2008-4686?
To fix CVE-2008-4686, update to VLC media player version 0.9.5 or later where the vulnerability has been addressed.
3
What products are affected by CVE-2008-4686?
VLC media player versions 0.9.0, 0.9.1, 0.9.2, 0.9.3, and 0.9.4 are affected by CVE-2008-4686.
4
What type of attacks can exploit CVE-2008-4686?
CVE-2008-4686 can be exploited by remote attackers through the use of a crafted .ty file.
5
Does CVE-2008-4686 affect all platforms running VLC?
Yes, CVE-2008-4686 affects all platforms that run the vulnerable versions of VLC media player.