FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-3468

This CVE name corresponds to:

Entered Topic
2007-06-18 vlc -- format string vulnerability and integer overflow

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-3468
Phase Assigned(20070627)

Description

input.c in VideoLAN VLC Media Player before 0.8.6c allows remote attackers to cause a denial of service (crash) via a crafted WAV file that causes an uninitialized i_nb_resamplers variable to be used.

References

Source Reference
BUGTRAQ 20070621 VLC 0.8.6b format string vulnerability & integer overflow
MISC http://www.isecpartners.com/advisories/2007-001-vlc.txt
DEBIAN DSA-1332
OSVDB 38992
OVAL oval:org.mitre.oval:def:14744
SECUNIA 25980