CVE-2008-3794
EPSS 9.2%
Description
Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote attackers to execute arbitrary code via a crafted mmst link with a negative size value, which bypasses a size check and triggers an integer overflow followed by a heap-based buffer overflow.
How to fix CVE-2008-3794
To remediate CVE-2008-3794, upgrade the affected package to a fixed version below.
- Debian/vlc—upgrade to 0.8.6.h-4 or later
Is CVE-2008-3794 being exploited?
Moderate — EPSS is 9.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 0.8.6.h-4