CVE-2008-2430

Publication date 7 July 2008

Last updated 24 July 2024


Ubuntu priority

Integer overflow in the Open function in modules/demux/wav.c in VLC Media Player 0.8.6h on Windows allows remote attackers to execute arbitrary code via a large fmt chunk in a WAV file.

Status

Package Ubuntu Release Status
vlc 9.10 karmic
Not affected
9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Fixed 0.8.6.release.e+x264svn20071224+faad2.6.1-0ubuntu3.1
7.10 gutsy Ignored end of life, was needed
7.04 feisty Ignored end of life, was needed
6.06 LTS dapper Ignored end of life