Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-3794

Опубликовано: 26 авг. 2008
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote attackers to execute arbitrary code via a crafted mmst link with a negative size value, which bypasses a size check and triggers an integer overflow followed by a heap-based buffer overflow.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:videolan:vlc_media_player:0.8.6i:*:*:*:*:*:*:*

EPSS

Процентиль: 93%
0.09199
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-189

Связанные уязвимости

ubuntu
больше 17 лет назад

Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote attackers to execute arbitrary code via a crafted mmst link with a negative size value, which bypasses a size check and triggers an integer overflow followed by a heap-based buffer overflow.

debian
больше 17 лет назад

Integer signedness error in the mms_ReceiveCommand function in modules ...

github
почти 4 года назад

Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote attackers to execute arbitrary code via a crafted mmst link with a negative size value, which bypasses a size check and triggers an integer overflow followed by a heap-based buffer overflow.

CVSS3: 5.6
fstec
больше 17 лет назад

Уязвимость функции mms_ReceiveCommand (modules/access/mms/mmstu.c) программы-медиапроигрывателя VideoLAN VLC, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 93%
0.09199
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-189