CVE-2008-4686

Source
https://nvd.nist.gov/vuln/detail/CVE-2008-4686
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2008-4686.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2008-4686
Published
2008-10-22T18:00:01Z
Modified
2025-04-09T00:30:58Z
Downstream
Summary
[none]
Details

Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote attackers to execute arbitrary code via a crafted .ty file, a different vulnerability than CVE-2008-4654.

References

Affected packages

Debian:11 / vlc

Package

Name
vlc
Purl
pkg:deb/debian/vlc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.8.6.h-4.1

Ecosystem specific

{
    "urgency": "medium"
}

Debian:12 / vlc

Package

Name
vlc
Purl
pkg:deb/debian/vlc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.8.6.h-4.1

Ecosystem specific

{
    "urgency": "medium"
}

Debian:13 / vlc

Package

Name
vlc
Purl
pkg:deb/debian/vlc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.8.6.h-4.1

Ecosystem specific

{
    "urgency": "medium"
}