FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-5036

This CVE name corresponds to:

Entered Topic
2008-11-08 vlc -- cue processing stack overflow

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-5036
Phase Assigned(20081110)

Description

Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execute arbitrary code via an an invalid RealText (rt) subtitle file, related to the ParseRealText function in modules/demux/subtitle.c. NOTE: this issue was SPLIT from CVE-2008-5032 on 20081110.

References

Source Reference
BUGTRAQ 20081106 [TKADV2008-011] VLC media player RealText Processing Stack Overflow Vulnerability
MILW0RM 7051
MLIST [oss-security] 20081105 CVE id request: vlc
MLIST [oss-security] 20081105 VideoLAN security advisory 0810
MLIST [oss-security] 20081110 Re: CVE id request: vlc
MISC http://www.trapkit.de/advisories/TKADV2008-011.txt
CONFIRM http://git.videolan.org/?p=vlc.git;a=commitdiff;h=e3cef651125701a2e33a8d75b815b3e39681a447
CONFIRM http://www.videolan.org/security/sa0810.html
GENTOO GLSA-200812-24
BID 32125
OVAL oval:org.mitre.oval:def:14329
SECUNIA 33315
SECUNIA 32569
XF vlcmediaplayer-realtext-bo(46376)