CVE-2007-6682
published 2008-01-17CVE-2007-6682: Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via…
PriorityP357high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
15.14%
96.3th percentile
Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via format string specifiers in the Connection parameter.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | vlc | < vlc 0.8.6.c-4.1 (bookworm) | vlc 0.8.6.c-4.1 (bookworm) |
| videolan | vlc | <= 0.8.6d | — |
| videolan | vlc_media_player | >= 0 < 0.8.6.c-4.1 | 0.8.6.c-4.1 |
| videolan | vlc_media_player | >= 0 < 0.8.6.c-4.1 | 0.8.6.c-4.1 |
| videolan | vlc_media_player | >= 0 < 0.8.6.c-4.1 | 0.8.6.c-4.1 |
| videolan | vlc_media_player | >= 0 < 0.8.6.c-4.1 | 0.8.6.c-4.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered via format string specifiers placed in the HTTP 'Connection:' header, sent to VLC's built-in HTTP server. Inspect HTTP requests to VLC's HTTP interface for format string tokens (e.g., %n, %x, %s) in the Connection header. ↗
- →The vulnerable function is httpd_FileCallBack in network/httpd.c. Monitor for crashes or anomalous behaviour in VLC's HTTP server thread (httpd_HostThread) as exploitation occurs within a thread context. ↗
- →The public exploit uses an EBP-chaining technique to achieve code execution from a thread stack. The shellcode is a BSD x86 reverse shell connecting back to LPORT=4321; monitor for unexpected outbound connections on port 4321 from VLC processes. ↗
- ·Debian marks the scope of this CVE as 'local', which may affect detection priority in network-only monitoring configurations, though the vulnerability is remotely exploitable via VLC's HTTP interface. ↗
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-prxp-p3xh-w4mq: Format string vulnerability in the httpd_FileCallBack function (network/httpd
ghsa_unreviewed·2022-05-01
CVE-2007-6682 [HIGH] GHSA-prxp-p3xh-w4mq: Format string vulnerability in the httpd_FileCallBack function (network/httpd
Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via format string specifiers in the Connection parameter.
OSV
CVE-2007-6682: Format string vulnerability in the httpd_FileCallBack function (network/httpd
osv·2008-01-17·CVSS 7.5
CVE-2007-6682 [HIGH] CVE-2007-6682: Format string vulnerability in the httpd_FileCallBack function (network/httpd
Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via format string specifiers in the Connection parameter.
Debian
CVE-2007-6682: vlc - Format string vulnerability in the httpd_FileCallBack function (network/httpd.c)...
vendor_debian·2007·CVSS 7.5
CVE-2007-6682 [HIGH] CVE-2007-6682: vlc - Format string vulnerability in the httpd_FileCallBack function (network/httpd.c)...
Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via format string specifiers in the Connection parameter.
Scope: local
bookworm: resolved (fixed in 0.8.6.c-4.1)
bullseye: resolved (fixed in 0.8.6.c-4.1)
forky: resolved (fixed in 0.8.6.c-4.1)
sid: resolved (fixed in 0.8.6.c-4.1)
trixie: resolved (fixed in 0.8.6.c-4.1)
No detection rules found.
Exploit-DB
Microsoft Office 2007 - MSPTLS Heap Index Integer Underflow (MS15-081)
exploitdb·2015-08-21
CVE-2015-2470 Microsoft Office 2007 - MSPTLS Heap Index Integer Underflow (MS15-081)
Microsoft Office 2007 - MSPTLS Heap Index Integer Underflow (MS15-081)
---
Source: https://code.google.com/p/google-security-research/issues/detail?id=431&can=1
The following crash was observed in Microsoft Office 2007 with Microsoft Office File Validation Add-In disabled and Application Verifier enabled for testing and reproduction. This bug also reproduced in Office 2010 running on Windows 7 x86.
The crash is caused by a 1 bit delta from the original file at offset 0xA9B0. Standard tools did not identify anything significant about this offset in the minimized file.
Attached files:
Fuzzed minimized PoC: 3423415565_min.doc
Fuzzed non-minimized PoC: 3423415565_crash.doc
Original non-fuzzed file: 3423415565_orig.doc
DLL Versions:
wwlib.dll: 12.0.6720.5000
msptls.dll: 12.0.6682.5000
Exploit-DB
VideoLAN VLC Media Player 0.8.6d - 'httpd_FileCallBack' Remote Format String
exploitdb·2008-04-28·CVSS 7.5
CVE-2007-6682 [HIGH] VideoLAN VLC Media Player 0.8.6d - 'httpd_FileCallBack' Remote Format String
VideoLAN VLC Media Player 0.8.6d - 'httpd_FileCallBack' Remote Format String
---
/* Epibite // bite since 1442
* pown meme ta mamie
*/
/* Advisory from Luigi Auriemma
* CVE-2007-6682 / format string in VideoLAN VLC 0.8.6d
*
* Description :
* Format string vulnerability in the httpd_FileCallBack
* function (network/httpd.c) in VideoLAN VLC 0.8.6d allows
* remote attackers to execute arbitrary code via format
* string specifiers in the Connection parameter.
*/
/* La faille n'a d'interet que dans un but d'apprentissage
* d'une technique avance d'exploitation des chaines de
* format.
*
* Toute la difficulte de l'exploitation est liee au fait
* que la chaine de format se trouve dans un thread, et
* la pile remplie avec des adresses du tas.
* On est donc oblige d'utiliser la technique dite d
No writeups or analysis indexed.
http://aluigi.altervista.org/adv/vlcboffs-adv.txthttp://osvdb.org/42208http://secunia.com/advisories/28233http://secunia.com/advisories/29284http://secunia.com/advisories/29766http://securityreason.com/securityalert/3550http://trac.videolan.org/vlc/changeset/23839http://www.debian.org/security/2008/dsa-1543http://www.gentoo.org/security/en/glsa/glsa-200803-13.xmlhttp://www.securityfocus.com/archive/1/485488/30/0/threadedhttp://www.securityfocus.com/bid/27015https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14790https://www.exploit-db.com/exploits/5519http://aluigi.altervista.org/adv/vlcboffs-adv.txthttp://osvdb.org/42208http://secunia.com/advisories/28233http://secunia.com/advisories/29284http://secunia.com/advisories/29766http://securityreason.com/securityalert/3550http://trac.videolan.org/vlc/changeset/23839http://www.debian.org/security/2008/dsa-1543http://www.gentoo.org/security/en/glsa/glsa-200803-13.xmlhttp://www.securityfocus.com/archive/1/485488/30/0/threadedhttp://www.securityfocus.com/bid/27015https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14790https://www.exploit-db.com/exploits/5519
2008-01-17
Published