CVE-2008-1489

Publication date 25 March 2008

Last updated 24 July 2024


Ubuntu priority

Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MP4 RDRF box that triggers a heap-based buffer overflow, a different vulnerability than CVE-2008-0984.

Status

Package Ubuntu Release Status
vlc 8.04 LTS hardy
Fixed 0.8.6.release.e+x264svn20071224+faad2.6.1-0ubuntu2
7.10 gutsy
Fixed 0.8.6.release.c-0ubuntu5.2
7.04 feisty
Fixed 0.8.6.release-0ubuntu4.2
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper
Fixed 0.8.4.debian-1ubuntu6.3

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
vlc