CVE-2008-1489

VLC 0.8.6e - Buffer Overflow

Title source: llm

Description

Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MP4 RDRF box that triggers a heap-based buffer overflow, a different vulnerability than CVE-2008-0984.

Exploits (1)

exploitdb WORKING POC
pythonlocalwindows
https://www.exploit-db.com/exploits/5498

Scores

EPSS 0.3321
EPSS Percentile 96.8%

Classification

CWE
CWE-189
Status draft

Affected Products (1)

videolan/vlc

Timeline

Published Mar 25, 2008
Tracked Since Feb 18, 2026