VulnerabilityModified
CVE-2008-0984
The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote attackers to overwrite arbitrary memory and execute arbitrary code via a malformed MP4 file.
HIGH 9.3EPSS 15.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.3%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote attackers to overwrite arbitrary memory and execute arbitrary code via a malformed MP4 file.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 15.28% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- miro/miro player · videolan/vlc media player
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060481.html
- http://secunia.com/advisories/29122Vendor Advisory
- http://secunia.com/advisories/29153Vendor Advisory
- http://secunia.com/advisories/29284Vendor Advisory
- http://secunia.com/advisories/29766Vendor Advisory
- http://www.coresecurity.com/?action=item&id=2147
- http://www.debian.org/security/2008/dsa-1543
- http://www.gentoo.org/security/en/glsa/glsa-200803-13.xml
- http://www.securityfocus.com/archive/1/488841/100/0/threaded
- http://www.securityfocus.com/bid/28007
- http://www.securitytracker.com/id?1019510
- http://www.videolan.org/security/sa0802.htmlPatch
- http://www.vupen.com/english/advisories/2008/0682Vendor Advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060481.html
- http://secunia.com/advisories/29122Vendor Advisory
- http://secunia.com/advisories/29153Vendor Advisory
- http://secunia.com/advisories/29284Vendor Advisory
- http://secunia.com/advisories/29766Vendor Advisory
- http://www.coresecurity.com/?action=item&id=2147
- http://www.debian.org/security/2008/dsa-1543
- http://www.gentoo.org/security/en/glsa/glsa-200803-13.xml
- http://www.securityfocus.com/archive/1/488841/100/0/threaded
- http://www.securityfocus.com/bid/28007
- http://www.securitytracker.com/id?1019510
- http://www.videolan.org/security/sa0802.htmlPatch
- http://www.vupen.com/english/advisories/2008/0682Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.