oss-sec mailing list archives
Re: CVE request: vlc
From: "Steven M. Christey" <coley () linus mitre org>
Date: Tue, 26 Feb 2008 13:45:09 -0500 (EST)
The tone of the VLC advisory suggests it's not ready for public release, but given the public nature of this list, I'm filling in the CVE description anyway. Use CVE-2008-0984 - Steve ====================================================== Name: CVE-2008-0984 Status: Candidate URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0984 Reference: CONFIRM:http://www.videolan.org/security/sa0802.html The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier allows remote attackers to overwrite arbitrary memory and execute arbitrary code via a malformed MP4 file.
Current thread:
- CVE request: vlc Nico Golde (Feb 26)
- Re: CVE request: vlc Steven M. Christey (Feb 26)
- Re: CVE request: vlc Nico Golde (Feb 26)
- Re: CVE request: vlc Steven M. Christey (Feb 26)