Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-5036
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-5036

Description:
Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execute arbitrary code via an an invalid RealText (rt) subtitle file, related to the ParseRealText function in modules/demux/subtitle.c. NOTE: this issue was SPLIT from CVE-2008-5032 on 20081110.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/46376

SAID
  Secunia Advisory: SA33315
  Secunia Advisory: SA32569

MLIST
  http://www.openwall.com/lists/oss-security/2008/11/10/13
  http://www.openwall.com/lists/oss-security/2008/11/05/4
  http://www.openwall.com/lists/oss-security/2008/11/05/5

MISC
  http://www.trapkit.de/advisories/TKADV2008-011.txt

MILW0RM
  http://www.milw0rm.com/exploits/7051

GENTOO
  http://security.gentoo.org/glsa/glsa-200812-24.xml

CONFIRM
  http://git.videolan.org/?p=vlc.git;a=commitdiff;h=e3cef651125701a2e33a8d75b815b3e39681a447
  http://www.videolan.org/security/sa0810.html

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/498111/100/0/threaded

BID
  32125


Return to the previous page.