FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-3467

This CVE name corresponds to:

Entered Topic
2007-06-18 vlc -- format string vulnerability and integer overflow

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-3467
Phase Assigned(20070627)

Description

Integer overflow in the __status_Update function in stats.c VideoLAN VLC Media Player before 0.8.6c allows remote attackers to cause a denial of service (crash) via a WAV file with a large sample rate.

References

Source Reference
BUGTRAQ 20070621 VLC 0.8.6b format string vulnerability & integer overflow
MISC http://www.isecpartners.com/advisories/2007-001-vlc.txt
DEBIAN DSA-1332
OSVDB 42189
OVAL oval:org.mitre.oval:def:14863
SECUNIA 25980