VulnerabilityModified
CVE-2008-4558
Array index error in VLC media player 0.9.2 allows remote attackers to overwrite arbitrary memory and execute arbitrary code via an XSPF playlist file with a negative identifier tag, which passes a signed comparison.
MEDIUM 6.8EPSS 8.49%
Does this matter?
Lower severity and a low EPSS score (8.49%). Track it; it rarely justifies an emergency change on its own.
Description
Array index error in VLC media player 0.9.2 allows remote attackers to overwrite arbitrary memory and execute arbitrary code via an XSPF playlist file with a negative identifier tag, which passes a signed comparison.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 8.49% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- videolan/vlc media player
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/32267Vendor Advisory
- http://www.coresecurity.com/content/vlc-xspf-memory-corruptionExploit
- http://www.exploit-db.com/exploits/6756
- http://www.securityfocus.com/archive/1/497354/100/0/threaded
- http://www.securityfocus.com/bid/31758
- http://www.vupen.com/english/advisories/2008/2826
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45869
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14726
- http://secunia.com/advisories/32267Vendor Advisory
- http://www.coresecurity.com/content/vlc-xspf-memory-corruptionExploit
- http://www.exploit-db.com/exploits/6756
- http://www.securityfocus.com/archive/1/497354/100/0/threaded
- http://www.securityfocus.com/bid/31758
- http://www.vupen.com/english/advisories/2008/2826
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45869
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14726
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.