CVE-2008-2147VLC vulnerability

CWE-2646 documents6 sources
Severity
4.6MEDIUMNVD
EPSS
0.1%
top 76.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12
Latest updateMay 1

Description

Untrusted search path vulnerability in VideoLAN VLC before 0.9.0 allows local users to execute arbitrary code via a malicious library under the modules/ or plugins/ subdirectories of the current working directory.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages2 packages

Debianvideolan/vlc_media_player< 0.8.6.e-2.2+3
NVDvideolan/vlc0.8.6+23

🔴Vulnerability Details

3
GHSA
GHSA-f2wq-qcrw-36wc: Untrusted search path vulnerability in VideoLAN VLC before 02022-05-01
CVEList
CVE-2008-2147: Untrusted search path vulnerability in VideoLAN VLC before 02008-05-12
OSV
CVE-2008-2147: Untrusted search path vulnerability in VideoLAN VLC before 02008-05-12

💥Exploits & PoCs

1
Exploit-DB
Avlc Forum - 'vlc_forum.php' SQL Injection2008-07-12

📋Vendor Advisories

1
Debian
CVE-2008-2147: vlc - Untrusted search path vulnerability in VideoLAN VLC before 0.9.0 allows local us...2008
CVE-2008-2147 — Videolan VLC vulnerability | cvebase