CVE-2007-0017

Description

Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and the (2) cdio_log_handler and (3) vcd_log_handler functions in modules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an invalid URI, as demonstrated by a udp://-- URI in an M3U file.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
59.645

Associated Vulnerability

VulnerabilityOS Platform
Update VLC Media Player 0.8.6a to latest versionWindows
Update VLC Media Player 0.8.6a (x64) to latest versionWindows
Multiple Vulnerabilities are affected in VLC Media Player (MSI) (x64) 0.7.0Windows
Multiple Vulnerabilities are affected in VLC Media Player (MSI) (x64) 0.7.1Windows
Multiple Vulnerabilities are affected in VLC Media Player (MSI) (x64) 0.7.2Windows
Multiple Vulnerabilities are affected in VLC Media Player (MSI) (x64) 0.8.0Windows
Multiple Vulnerabilities are affected in VLC Media Player (MSI) (x64) 0.8.1Windows
Multiple Vulnerabilities are affected in VLC Media Player (MSI) (x64) 0.8.2Windows
Multiple Vulnerabilities are affected in VLC Media Player (MSI) (x64) 0.8.4Windows
Multiple Vulnerabilities are affected in VLC Media Player (MSI) (x64) 0.8.4aWindows
Multiple Vulnerabilities are affected in VLC Media Player (MSI) (x64) 0.8.5Windows
Multiple Vulnerabilities are affected in VLC Media Player (MSI) (x64) 0.8.6Windows
Multiple Vulnerabilities are affected in VLC media player (MSI) 0.7.0Windows
Multiple Vulnerabilities are affected in VLC media player (MSI) 0.7.1Windows
Multiple Vulnerabilities are affected in VLC media player (MSI) 0.7.2Windows
Multiple Vulnerabilities are affected in VLC media player (MSI) 0.8.0Windows
Multiple Vulnerabilities are affected in VLC media player (MSI) 0.8.1Windows
Multiple Vulnerabilities are affected in VLC media player (MSI) 0.8.2Windows
Multiple Vulnerabilities are affected in VLC media player (MSI) 0.8.4Windows
Multiple Vulnerabilities are affected in VLC media player (MSI) 0.8.4aWindows
Multiple Vulnerabilities are affected in VLC media player (MSI) 0.8.5Windows
Multiple Vulnerabilities are affected in VLC media player (MSI) 0.8.6Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-339134VLC Media Player (3.0.21)
PATCH-339135VLC Media Player (X64) (3.0.21)
PATCH-334048VLC media player (MSI) (x64) (3.0.20.0)
PATCH-334048VLC media player (MSI) (x64) (3.0.20.0)
PATCH-334048VLC media player (MSI) (x64) (3.0.20.0)
PATCH-334048VLC media player (MSI) (x64) (3.0.20.0)
PATCH-334048VLC media player (MSI) (x64) (3.0.20.0)
PATCH-334048VLC media player (MSI) (x64) (3.0.20.0)
PATCH-334048VLC media player (MSI) (x64) (3.0.20.0)
PATCH-334048VLC media player (MSI) (x64) (3.0.20.0)
PATCH-334048VLC media player (MSI) (x64) (3.0.20.0)
PATCH-334048VLC media player (MSI) (x64) (3.0.20.0)
PATCH-334050VLC media player (MSI) (3.0.20.0)
PATCH-334050VLC media player (MSI) (3.0.20.0)
PATCH-334050VLC media player (MSI) (3.0.20.0)
PATCH-334050VLC media player (MSI) (3.0.20.0)
PATCH-334050VLC media player (MSI) (3.0.20.0)
PATCH-334050VLC media player (MSI) (3.0.20.0)
PATCH-334050VLC media player (MSI) (3.0.20.0)
PATCH-334050VLC media player (MSI) (3.0.20.0)
PATCH-334050VLC media player (MSI) (3.0.20.0)
PATCH-334050VLC media player (MSI) (3.0.20.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234