Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.58453
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1332-1)
Summary:The remote host is missing an update for the Debian 'vlc' package(s) announced via the DSA-1332-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'vlc' package(s) announced via the DSA-1332-1 advisory.

Vulnerability Insight:
Several remote vulnerabilities have been discovered in the VideoLan multimedia player and streamer, which may lead to the execution of arbitrary code. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2007-3316

David Thiel discovered that several format string vulnerabilities may lead to the execution of arbitrary code.

CVE-2007-3467

David Thiel discovered an integer overflow in the WAV processing code.

This update also fixes several crashes, which can be triggered through malformed media files.

For the oldstable distribution (sarge) these problems have been fixed in version 0.8.1.svn20050314-1sarge3. Packages for the powerpc architecture are not yet available. They will be provided later.

For the stable distribution (etch) these problems have been fixed in version 0.8.6-svn20061012.debian-5etch1.

For the unstable distribution (sid) these problems have been fixed in version 0.8.6.c-1.

We recommend that you upgrade your vlc packages.

Affected Software/OS:
'vlc' package(s) on Debian 3.1, Debian 4.

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-3316
BugTraq ID: 24555
http://www.securityfocus.com/bid/24555
Bugtraq: 20070621 VLC 0.8.6b format string vulnerability & integer overflow (Google Search)
http://www.securityfocus.com/archive/1/471933/100/0/threaded
CERT/CC vulnerability note: VU#200928
http://www.kb.cert.org/vuls/id/200928
Debian Security Information: DSA-1332 (Google Search)
http://www.debian.org/security/2007/dsa-1332
http://security.gentoo.org/glsa/glsa-200707-12.xml
http://www.isecpartners.com/advisories/2007-001-vlc.txt
http://osvdb.org/37379
http://osvdb.org/37380
http://osvdb.org/37381
http://osvdb.org/37382
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14600
http://secunia.com/advisories/25753
http://secunia.com/advisories/25980
http://secunia.com/advisories/26269
http://www.vupen.com/english/advisories/2007/2262
Common Vulnerability Exposure (CVE) ID: CVE-2007-3467
http://osvdb.org/42189
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14863
Common Vulnerability Exposure (CVE) ID: CVE-2007-3468
http://osvdb.org/38992
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14744
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.