Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Mai Xuan Cuong

#42503de 56,330
6.8CVSS total
Vulnerabilidades · 1
PT-2008-1148
6.8
2008-04-17
Videolan · Vlc · CVE-2008-1881
**Name of the Vulnerable Software and Affected Versions** VLC version 0.8.6e **Description** The issue is related to a stack-based buffer overflow in the `ParseSSA` function, located in `modules/demux/subtitle.c`. This allows remote attackers to execute arbitrary code via a long subtitle in an SSA file. The problem is due to an incomplete fix for a previous issue. **Recommendations** For VLC version 0.8.6e, consider disabling the `ParseSSA` function as a temporary workaround until a patch is available. Restrict access to SSA files to minimize the risk of exploitation.