CVE-2008-3732
published 2008-08-20CVE-2008-3732: Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (application…
PriorityP350critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
13.43%
96.0th percentile
Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TTA file, which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | vlc | < vlc 0.8.6.h-2 (bookworm) | vlc 0.8.6.h-2 (bookworm) |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | >= 0 < 0.8.6.h-2 | 0.8.6.h-2 |
| videolan | vlc_media_player | >= 0 < 0.8.6.h-2 | 0.8.6.h-2 |
| videolan | vlc_media_player | >= 0 < 0.8.6.h-2 | 0.8.6.h-2 |
| videolan | vlc_media_player | >= 0 < 0.8.6.h-2 | 0.8.6.h-2 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f82v-mcfc-hrmc: Integer overflow in the Open function in modules/demux/tta
ghsa_unreviewed·2022-05-02
CVE-2008-3732 [HIGH] GHSA-f82v-mcfc-hrmc: Integer overflow in the Open function in modules/demux/tta
Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TTA file, which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.
OSV
CVE-2008-3732: Integer overflow in the Open function in modules/demux/tta
osv·2008-08-20·CVSS 9.3
CVE-2008-3732 [CRITICAL] CVE-2008-3732: Integer overflow in the Open function in modules/demux/tta
Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TTA file, which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.
Debian
CVE-2008-3732: vlc - Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player...
vendor_debian·2008·CVSS 9.3
CVE-2008-3732 [CRITICAL] CVE-2008-3732: vlc - Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player...
Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TTA file, which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 0.8.6.h-2)
bullseye: resolved (fixed in 0.8.6.h-2)
forky: resolved (fixed in 0.8.6.h-2)
sid: resolved (fixed in 0.8.6.h-2)
trixie: resolved (fixed in 0.8.6.h-2)
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/31512http://security.gentoo.org/glsa/glsa-200809-06.xmlhttp://securityreason.com/securityalert/4170http://www.orange-bat.com/adv/2008/adv.08.16.txthttp://www.securityfocus.com/bid/30718http://www.vupen.com/english/advisories/2008/2394https://exchange.xforce.ibmcloud.com/vulnerabilities/44510https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14570https://www.exploit-db.com/exploits/6252http://secunia.com/advisories/31512http://security.gentoo.org/glsa/glsa-200809-06.xmlhttp://securityreason.com/securityalert/4170http://www.orange-bat.com/adv/2008/adv.08.16.txthttp://www.securityfocus.com/bid/30718http://www.vupen.com/english/advisories/2008/2394https://exchange.xforce.ibmcloud.com/vulnerabilities/44510https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14570https://www.exploit-db.com/exploits/6252
2008-08-20
Published