>> VLC Media Player "ReadRealIndex()" Integer Overflow Vulnerability
Title : VLC Media Player "ReadRealIndex()" Integer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-3287 CVE ID : CVE-2008-5276 CWE ID : CWE-189
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-12-01
A vulnerability has been identified in VLC Media Player, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an integer overflow error in the "ReadRealIndex()" [modules/demux/real.c] function when parsing a malformed RealMedia (.rm) file, which could allow attackers to crash an affected application or execute arbitrary code by tricking a user into opening a specially crafted file.