Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2007-0017

Опубликовано: 03 янв. 2007
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 6.8

Описание

Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and the (2) cdio_log_handler and (3) vcd_log_handler functions in modules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an invalid URI, as demonstrated by a udp://-- URI in an M3U file.

РелизСтатусПримечание
dapper

released

0.8.4.debian-1ubuntu6.1
devel

released

0.8.6.release-0ubuntu4
edgy

released

0.8.6-svn20061012.debian-1ubuntu1.1
feisty

released

0.8.6.release-0ubuntu4
upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 98%
0.47255
Средний

6.8 Medium

CVSS2

Связанные уязвимости

nvd
больше 18 лет назад

Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and the (2) cdio_log_handler and (3) vcd_log_handler functions in modules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an invalid URI, as demonstrated by a udp://-- URI in an M3U file.

debian
больше 18 лет назад

Multiple format string vulnerabilities in (1) the cdio_log_handler fun ...

github
больше 3 лет назад

Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and the (2) cdio_log_handler and (3) vcd_log_handler functions in modules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an invalid URI, as demonstrated by a udp://-- URI in an M3U file.

CVSS3: 5
fstec
больше 18 лет назад

Множественные уязвимости функций cdio_log_handler (modules/access/cdda/access.c) плагина CDDA (libcdda_plugin) и cdio_log_handler, vcd_log_handler (modules/access/vcdx/access.c) плагина VCDX (libvcdx_plugin) программы-медиапроигрывателя VideoLAN VLC, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 98%
0.47255
Средний

6.8 Medium

CVSS2