CVE-2007-0017
vlc
EPSS 12.0%
描述
Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and the (2) cdio_log_handler and (3) vcd_log_handler functions in modules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an invalid URI, as demonstrated by a udp://-- URI in an M3U file.
如何修補 CVE-2007-0017
要修補 CVE-2007-0017,請將受影響套件升級到下列已修補版本。
- Debian/vlc—升級至 0.8.6-svn20061012.debian-1.2 或更新版本
- —升級至 0.8.1.svn20050314-1sarge2 或更新版本
CVE-2007-0017 正在被利用嗎?
中等 — EPSS 為 12.0%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 0.8.6-svn20061012.debian-1.2
- from 0, < 0.8.1.svn20050314-1sarge2