FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-3316

This CVE name corresponds to:

Entered Topic
2007-06-18 vlc -- format string vulnerability and integer overflow

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-3316
Phase Assigned(20070621)

Description

Multiple format string vulnerabilities in plugins in VideoLAN VLC Media Player before 0.8.6c allow remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in (1) an Ogg/Vorbis file, (2) an Ogg/Theora file, (3) a CDDB entry for a CD Digital Audio (CDDA) file, or (4) Service Announce Protocol (SAP) multicast packets.

References

Source Reference
BUGTRAQ 20070621 VLC 0.8.6b format string vulnerability & integer overflow
MISC http://www.isecpartners.com/advisories/2007-001-vlc.txt
CONFIRM http://www.videolan.org/sa0702.html
DEBIAN DSA-1332
GENTOO GLSA-200707-12
CERT-VN VU#200928
BID 24555
OSVDB 37379
OSVDB 37380
OSVDB 37381
OSVDB 37382
OVAL oval:org.mitre.oval:def:14600
VUPEN ADV-2007-2262
SECUNIA 25753
SECUNIA 25980
SECUNIA 26269