CVE-2007-3468
EPSS 1.0%
Description
input.c in VideoLAN VLC Media Player before 0.8.6c allows remote attackers to cause a denial of service (crash) via a crafted WAV file that causes an uninitialized i_nb_resamplers variable to be used.
How to fix CVE-2007-3468
To remediate CVE-2007-3468, upgrade the affected package to a fixed version below.
- Debian/vlc—upgrade to 0.8.6.c.debian-1 or later
Is CVE-2007-3468 being exploited?
Low — EPSS is 1.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.8.6.c.debian-1