CVE-2008-5032: Buffer Overflow
Stack-based buffer overflow in VideoLAN VLC media player 0.5.0 through 0.9.5 might allow user-assisted attackers to execute arbitrary code via the header of an invalid CUE image file, related to modules/access/vcd/cdrom.c. NOTE: this identifier originally included an issue related to RealText, but that issue has been assigned a separate identifier, CVE-2008-5036.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5032?
CVE-2008-5032 is classified as a medium severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2008-5032?
To fix CVE-2008-5032, users should upgrade to a version of VLC media player that is not affected, specifically version 0.9.6 or later.
What systems are affected by CVE-2008-5032?
CVE-2008-5032 affects multiple versions of VideoLAN VLC media player, specifically versions 0.5.0 through 0.9.5.
Is user interaction required for CVE-2008-5032 to be exploited?
Yes, exploiting CVE-2008-5032 typically requires user interaction to open a specially crafted CUE image file.
What type of vulnerability is CVE-2008-5032?
CVE-2008-5032 is a stack-based buffer overflow vulnerability.