CVE-2008-0984
Summary
| CVE | CVE-2008-0984 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-02-26 19:44:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote attackers to overwrite arbitrary memory and execute arbitrary code via a malformed MP4 file. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Miro | Miro Player | All | All | All | All |
| Application | Videolan | Vlc Media Player | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VideoLAN VLC Media Player MP4 Demuxer Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Miro MP4 Demuxer Arbitrary Memory Overwrite - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| VideoLAN Security Advisory 0802 | af854a3a-2127-422b-91ae-364da2661108 | www.videolan.org | Patch |
| VLC: Multiple vulnerabilities — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Core Security | Cyber Threat Prevention & Identity Governance | af854a3a-2127-422b-91ae-364da2661108 | www.coresecurity.com | |
| VLC Media Player MP4 Demuxer Arbitrary Memory Overwrite - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Debian -- Security Information -- DSA-1543-1 vlc | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [Full-disclosure] [ MDVSA-2008:052 ] - Updated cacti packages fix multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | lists.grok.org.uk | |
| Gentoo update for vlc - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| VLC Media Player MPEG-4 Demuxer Memory Corruption Flaw Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Debian update for vlc - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.