CVE Database
/

CVE-2007-0017

Back to search

CVE-2007-0017

Published: Jan 3, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and the (2) cdio_log_handler and (3) vcd_log_handler functions in modules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an invalid URI, as demonstrated by a udp://-- URI in an M3U file.

VendorProductVersions

n/a

n/a

affected
n/a

References

21852
vdb-entry
x_refsource_BID
ADV-2007-0026
vdb-entry
x_refsource_VUPEN
23971
third-party-advisory
x_refsource_SECUNIA
31163
vdb-entry
x_refsource_OSVDB
SUSE-SA:2007:013
vendor-advisory
x_refsource_SUSE
1017464
vdb-entry
x_refsource_SECTRACK
23829
third-party-advisory
x_refsource_SECUNIA
23592
third-party-advisory
x_refsource_SECUNIA
23910
third-party-advisory
x_refsource_SECUNIA
GLSA-200701-24
vendor-advisory
x_refsource_GENTOO
oval:org.mitre.oval:def:14313
vdb-entry
signature
x_refsource_OVAL
DSA-1252
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now