CVE-2007-3316

Publication date 21 June 2007

Last updated 24 July 2024


Ubuntu priority

Multiple format string vulnerabilities in plugins in VideoLAN VLC Media Player before 0.8.6c allow remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in (1) an Ogg/Vorbis file, (2) an Ogg/Theora file, (3) a CDDB entry for a CD Digital Audio (CDDA) file, or (4) Service Announce Protocol (SAP) multicast packets.

Status

Package Ubuntu Release Status
vlc 9.10 karmic
Fixed 0.8.6.release.c-0ubuntu3
9.04 jaunty
Fixed 0.8.6.release.c-0ubuntu3
8.10 intrepid
Fixed 0.8.6.release.c-0ubuntu3
8.04 LTS hardy
Fixed 0.8.6.release.c-0ubuntu3
7.10 gutsy
Fixed 0.8.6.release.c-0ubuntu3
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life