CVE-2008-1881

Publication date 17 April 2008

Last updated 24 July 2024


Ubuntu priority

Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a long subtitle in an SSA file. NOTE: this issue is due to an incomplete fix for CVE-2007-6681.

Status

Package Ubuntu Release Status
vlc 9.10 karmic
Fixed 0.8.6.release.e+zdebian-2.3ubuntu1
9.04 jaunty
Fixed 0.8.6.release.e+zdebian-2.3ubuntu1
8.10 intrepid
Fixed 0.8.6.release.e+zdebian-2.3ubuntu1
8.04 LTS hardy
Fixed 0.8.6.release.e+x264svn20071224+faad2.6.1-0ubuntu3.1
7.10 gutsy Ignored end of life, was needed
7.04 feisty Ignored end of life, was needed
6.06 LTS dapper Ignored end of life