Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2007-6683

Опубликовано: 17 янв. 2008
Источник: debian

Описание

The browser plugin in VideoLAN VLC 0.8.6d allows remote attackers to overwrite arbitrary files via (1) the :demuxdump-file option in a filename in a playlist, or (2) a EXTVLCOPT statement in an MP3 file, possibly an argument injection vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
vlcfixed0.8.6.c-4.1package
mozilla-browser-pluginfixed0.8.6.e-2.2package
vlcfixed0.8.6.c-4.1~lenny1lennypackage

Примечания

  • the plugin is in the same srcpkg but has its own implementation for VLCOPT

  • see https://trac.videolan.org/vlc/ticket/1371

Связанные уязвимости

ubuntu
около 18 лет назад

The browser plugin in VideoLAN VLC 0.8.6d allows remote attackers to overwrite arbitrary files via (1) the :demuxdump-file option in a filename in a playlist, or (2) a EXTVLCOPT statement in an MP3 file, possibly an argument injection vulnerability.

nvd
около 18 лет назад

The browser plugin in VideoLAN VLC 0.8.6d allows remote attackers to overwrite arbitrary files via (1) the :demuxdump-file option in a filename in a playlist, or (2) a EXTVLCOPT statement in an MP3 file, possibly an argument injection vulnerability.

github
почти 4 года назад

The browser plugin in VideoLAN VLC 0.8.6d allows remote attackers to overwrite arbitrary files via (1) the :demuxdump-file option in a filename in a playlist, or (2) a EXTVLCOPT statement in an MP3 file, possibly an argument injection vulnerability.