Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.60869
Category:Gentoo Local Security Checks
Title:Gentoo Security Advisory GLSA 200804-25 (vlc)
Summary:The remote host is missing updates announced in;advisory GLSA 200804-25.
Description:Summary:
The remote host is missing updates announced in
advisory GLSA 200804-25.

Vulnerability Insight:
Multiple vulnerabilities were found in VLC, allowing for the execution of
arbitrary code.

Solution:
All VLC users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose '>=media-video/vlc-0.8.6f'

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-6681
BugTraq ID: 27015
http://www.securityfocus.com/bid/27015
Bugtraq: 20071224 Buffer-overflow and format string in VideoLAN VLC 0.8.6d (Google Search)
http://www.securityfocus.com/archive/1/485488/30/0/threaded
Debian Security Information: DSA-1543 (Google Search)
http://www.debian.org/security/2008/dsa-1543
https://www.exploit-db.com/exploits/5667
http://www.gentoo.org/security/en/glsa/glsa-200803-13.xml
http://security.gentoo.org/glsa/glsa-200804-25.xml
http://aluigi.altervista.org/adv/vlcboffs-adv.txt
http://mailman.videolan.org/pipermail/vlc-devel/2007-June/032672.html
http://mailman.videolan.org/pipermail/vlc-devel/2007-June/033394.html
http://osvdb.org/42207
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14334
http://secunia.com/advisories/28233
http://secunia.com/advisories/29284
http://secunia.com/advisories/29766
http://secunia.com/advisories/29800
http://securityreason.com/securityalert/3550
Common Vulnerability Exposure (CVE) ID: CVE-2008-0073
BugTraq ID: 28312
http://www.securityfocus.com/bid/28312
Debian Security Information: DSA-1536 (Google Search)
http://www.debian.org/security/2008/dsa-1536
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00456.html
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00143.html
http://security.gentoo.org/glsa/glsa-200808-01.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2008:178
http://www.mandriva.com/security/advisories?name=MDVSA-2008:219
http://secunia.com/secunia_research/2008-10/
http://www.securitytracker.com/id?1019682
http://secunia.com/advisories/28694
http://secunia.com/advisories/29392
http://secunia.com/advisories/29472
http://secunia.com/advisories/29503
http://secunia.com/advisories/29578
http://secunia.com/advisories/29601
http://secunia.com/advisories/29740
http://secunia.com/advisories/30581
http://secunia.com/advisories/31372
http://secunia.com/advisories/31393
http://www.slackware.org/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.392408
SuSE Security Announcement: SUSE-SR:2008:007 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00008.html
SuSE Security Announcement: SUSE-SR:2008:012 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.html
http://www.ubuntu.com/usn/usn-635-1
http://www.vupen.com/english/advisories/2008/0923
http://www.vupen.com/english/advisories/2008/0985
XForce ISS Database: xinelib-sdpplinparse-bo(41339)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41339
Common Vulnerability Exposure (CVE) ID: CVE-2008-1489
BugTraq ID: 28433
http://www.securityfocus.com/bid/28433
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14841
XForce ISS Database: vlcmediaplayer-mp4readbox-rdrf-bo(41412)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41412
Common Vulnerability Exposure (CVE) ID: CVE-2008-1768
BugTraq ID: 28903
http://www.securityfocus.com/bid/28903
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14412
Common Vulnerability Exposure (CVE) ID: CVE-2008-1769
BugTraq ID: 28904
http://www.securityfocus.com/bid/28904
http://bugs.gentoo.org/show_bug.cgi?id=214627#c3
http://git.videolan.org/gitweb.cgi/vlc.git/?a=commit;h=cf489d7bff3c1b36b2d5501ecf21129c78104d98
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14445
Common Vulnerability Exposure (CVE) ID: CVE-2008-1881
BugTraq ID: 28251
http://www.securityfocus.com/bid/28251
BugTraq ID: 28274
http://www.securityfocus.com/bid/28274
Bugtraq: 20080317 VLC highlander bug (Google Search)
http://www.securityfocus.com/archive/1/489698
https://www.exploit-db.com/exploits/5250
http://aluigi.org/adv/vlcboffs-adv.txt
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14872
XForce ISS Database: vlc-parsessa-bo(41936)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41936
XForce ISS Database: vlcmediaplayer-subtitle-bo(41237)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41237
CopyrightCopyright (C) 2008 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.