CVE-2008-4686
Description
Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote attackers to execute arbitrary code via a crafted .ty file, a different vulnerability than CVE-2008-4654.
Risk Information
Base Score
7.8
MODERATE
Vector
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
8.258
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities affected in VLC Media Player (X64) 0.9.4 | Windows |
| Multiple vulnerabilities affected in VLC Media Player 0.9.4 | Windows |
| Multiple Vulnerabilities are affected in VLC Media Player (MSI) (x64) 0.9.2 | Windows |
| Multiple Vulnerabilities are affected in VLC media player (MSI) 0.9.2 | Windows |
| Multiple Vulnerabilities are affected in VLC Media Player (MSI) (x64) 0.9.1 | Windows |
| Multiple Vulnerabilities are affected in VLC Media Player (MSI) (x64) 0.9.3 | Windows |
| Multiple Vulnerabilities are affected in VLC Media Player (MSI) (x64) 0.9.4 | Windows |
| Multiple Vulnerabilities are affected in VLC media player (MSI) 0.9.1 | Windows |
| Multiple Vulnerabilities are affected in VLC media player (MSI) 0.9.3 | Windows |
| Multiple Vulnerabilities are affected in VLC media player (MSI) 0.9.4 | Windows |
| Multiple Vulnerabilities are affected in VLC Media Player (MSI) (x64) 0.9.0 | Windows |
| Multiple Vulnerabilities are affected in VLC media player (MSI) 0.9.0 | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-339135 | VLC Media Player (X64) (3.0.21) |
| PATCH-339134 | VLC Media Player (3.0.21) |
| PATCH-334048 | VLC media player (MSI) (x64) (3.0.20.0) |
| PATCH-334050 | VLC media player (MSI) (3.0.20.0) |
| PATCH-334048 | VLC media player (MSI) (x64) (3.0.20.0) |
| PATCH-334048 | VLC media player (MSI) (x64) (3.0.20.0) |
| PATCH-334048 | VLC media player (MSI) (x64) (3.0.20.0) |
| PATCH-334050 | VLC media player (MSI) (3.0.20.0) |
| PATCH-334050 | VLC media player (MSI) (3.0.20.0) |
| PATCH-334050 | VLC media player (MSI) (3.0.20.0) |
| PATCH-334048 | VLC media player (MSI) (x64) (3.0.20.0) |
| PATCH-334050 | VLC media player (MSI) (3.0.20.0) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234