CVE-2008-4654
EPSS 57.5%
描述
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player 0.9.0 through 0.9.4 allows remote attackers to execute arbitrary code via a TiVo TY media file with a header containing a crafted size value.
如何修補 CVE-2008-4654
要修補 CVE-2008-4654,請將受影響套件升級到下列已修補版本。
- Debian/vlc—升級至 1.0.3-1 或更新版本
CVE-2008-4654 正在被利用嗎?
可能 — EPSS 為 57.5%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, < 1.0.3-1