FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-5032

This CVE name corresponds to:

Entered Topic
2008-11-08 vlc -- cue processing stack overflow

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-5032
Phase Assigned(20081110)

Description

Stack-based buffer overflow in VideoLAN VLC media player 0.5.0 through 0.9.5 might allow user-assisted attackers to execute arbitrary code via the header of an invalid CUE image file, related to modules/access/vcd/cdrom.c. NOTE: this identifier originally included an issue related to RealText, but that issue has been assigned a separate identifier, CVE-2008-5036.

References

Source Reference
BUGTRAQ 20081106 [TKADV2008-012] VLC media player cue Processing Stack Overflow Vulnerability
MLIST [oss-security] 20081105 CVE id request: vlc
MLIST [oss-security] 20081105 VideoLAN security advisory 0810
MLIST [oss-security] 20081110 Re: CVE id request: vlc
MISC http://www.trapkit.de/advisories/TKADV2008-012.txt
CONFIRM http://git.videolan.org/?p=vlc.git;a=commitdiff;h=5f63f1562d43f32331006c2c1a61742de031b84d
CONFIRM http://www.videolan.org/security/sa0810.html
GENTOO GLSA-200812-24
BID 32125
OVAL oval:org.mitre.oval:def:14798
SECUNIA 33315
SECUNIA 32569
XF vlcmediaplayer-cue-bo(46375)