Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.64255
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1819-1)
Summary:The remote host is missing an update for the Debian 'vlc' package(s) announced via the DSA-1819-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'vlc' package(s) announced via the DSA-1819-1 advisory.

Vulnerability Insight:
Several vulnerabilities have been discovered in vlc, a multimedia player and streamer. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2008-1768

Drew Yao discovered that multiple integer overflows in the MP4 demuxer, Real demuxer and Cinepak codec can lead to the execution of arbitrary code.

CVE-2008-1769

Drew Yao discovered that the Cinepak codec is prone to a memory corruption, which can be triggered by a crafted Cinepak file.

CVE-2008-1881

Luigi Auriemma discovered that it is possible to execute arbitrary code via a long subtitle in an SSA file.

CVE-2008-2147

It was discovered that vlc is prone to a search path vulnerability, which allows local users to perform privilege escalations.

CVE-2008-2430

Alin Rad Pop discovered that it is possible to execute arbitrary code when opening a WAV file containing a large fmt chunk.

CVE-2008-3794

Pinar Yanardag discovered that it is possible to execute arbitrary code when opening a crafted mmst link.

CVE-2008-4686

Tobias Klein discovered that it is possible to execute arbitrary code when opening a crafted .ty file.

CVE-2008-5032

Tobias Klein discovered that it is possible to execute arbitrary code when opening an invalid CUE image file with a crafted header.

For the oldstable distribution (etch), these problems have been fixed in version 0.8.6-svn20061012.debian-5.1+etch3.

For the stable distribution (lenny), these problems have been fixed in version 0.8.6.h-4+lenny2, which was already included in the lenny release.

For the testing distribution (squeeze) and the unstable distribution (sid), these problems have been fixed in version 0.8.6.h-5.

We recommend that you upgrade your vlc packages.

Affected Software/OS:
'vlc' package(s) on Debian 4.

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-1768
BugTraq ID: 28903
http://www.securityfocus.com/bid/28903
http://security.gentoo.org/glsa/glsa-200804-25.xml
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14412
http://secunia.com/advisories/29503
http://secunia.com/advisories/29800
http://www.vupen.com/english/advisories/2008/0985
Common Vulnerability Exposure (CVE) ID: CVE-2008-1769
BugTraq ID: 28904
http://www.securityfocus.com/bid/28904
http://bugs.gentoo.org/show_bug.cgi?id=214627#c3
http://git.videolan.org/gitweb.cgi/vlc.git/?a=commit;h=cf489d7bff3c1b36b2d5501ecf21129c78104d98
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14445
Common Vulnerability Exposure (CVE) ID: CVE-2008-1881
BugTraq ID: 28251
http://www.securityfocus.com/bid/28251
BugTraq ID: 28274
http://www.securityfocus.com/bid/28274
Bugtraq: 20080317 VLC highlander bug (Google Search)
http://www.securityfocus.com/archive/1/489698
https://www.exploit-db.com/exploits/5250
http://aluigi.altervista.org/adv/vlcboffs-adv.txt
http://aluigi.org/adv/vlcboffs-adv.txt
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14872
http://secunia.com/advisories/28233
XForce ISS Database: vlc-parsessa-bo(41936)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41936
XForce ISS Database: vlcmediaplayer-subtitle-bo(41237)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41237
Common Vulnerability Exposure (CVE) ID: CVE-2008-2147
http://security.gentoo.org/glsa/glsa-200807-13.xml
http://secunia.com/advisories/31317
XForce ISS Database: vlc-searchpath-code-execution(42377)
https://exchange.xforce.ibmcloud.com/vulnerabilities/42377
Common Vulnerability Exposure (CVE) ID: CVE-2008-2430
BugTraq ID: 30058
http://www.securityfocus.com/bid/30058
Bugtraq: 20080702 Secunia Research: VLC Media Player WAV Processing Integer Overflow (Google Search)
http://www.securityfocus.com/archive/1/493849/100/0/threaded
http://secunia.com/secunia_research/2008-29/advisory/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14344
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14769
http://www.securitytracker.com/id?1020429
http://secunia.com/advisories/30601
http://securityreason.com/securityalert/3976
http://www.vupen.com/english/advisories/2008/1995/references
Common Vulnerability Exposure (CVE) ID: CVE-2008-3794
BugTraq ID: 30806
http://www.securityfocus.com/bid/30806
https://www.exploit-db.com/exploits/6293
http://security.gentoo.org/glsa/glsa-200809-06.xml
http://www.orange-bat.com/adv/2008/adv.08.24.txt
http://www.openwall.com/lists/oss-security/2008/08/24/3
http://mailman.videolan.org/pipermail/vlc-devel/2008-August/048488.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14531
http://www.securitytracker.com/id?1020759
http://securityreason.com/securityalert/4190
XForce ISS Database: vlcmediaplayer-memmove-bo(44659)
https://exchange.xforce.ibmcloud.com/vulnerabilities/44659
Common Vulnerability Exposure (CVE) ID: CVE-2008-4686
BugTraq ID: 31867
http://www.securityfocus.com/bid/31867
http://www.openwall.com/lists/oss-security/2008/10/19/2
http://www.openwall.com/lists/oss-security/2008/10/22/6
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14630
Common Vulnerability Exposure (CVE) ID: CVE-2008-5032
BugTraq ID: 32125
http://www.securityfocus.com/bid/32125
Bugtraq: 20081106 [TKADV2008-012] VLC media player cue Processing Stack Overflow Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/498112/100/0/threaded
http://security.gentoo.org/glsa/glsa-200812-24.xml
http://www.trapkit.de/advisories/TKADV2008-012.txt
http://www.openwall.com/lists/oss-security/2008/11/05/5
http://www.openwall.com/lists/oss-security/2008/11/05/4
http://www.openwall.com/lists/oss-security/2008/11/10/13
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14798
http://secunia.com/advisories/32569
http://secunia.com/advisories/33315
XForce ISS Database: vlcmediaplayer-cue-bo(46375)
https://exchange.xforce.ibmcloud.com/vulnerabilities/46375
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.