CVE-2008-3732

VLC Media Player <0.8.6i - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-3732. PoCs published by g_.

AI-analyzed exploit summary The advisory describes a heap overflow vulnerability in VLC 0.8.6i due to improper handling of TTA file metadata, leading to a denial-of-service condition. The issue arises from an integer overflow in the calculation of the seek table size, allowing an attacker to trigger excessive memory allocation and overwrites.

Description

Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TTA file, which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WRITEUP VERIFIED
by g_ · textdosmultiple
https://www.exploit-db.com/exploits/6252

The advisory describes a heap overflow vulnerability in VLC 0.8.6i due to improper handling of TTA file metadata, leading to a denial-of-service condition. The issue arises from an integer overflow in the calculation of the seek table size, allowing an attacker to trigger excessive memory allocation and overwrites.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: VLC 0.8.6i
No auth needed
Prerequisites: A maliciously crafted TTA file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14570
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6252
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30718
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31512
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/44510
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200809-06.xml
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4170
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2394

Scores

EPSS 0.1343
EPSS Percentile 96.0%

Details

CWE
CWE-189
Status published
Products (1)
videolan/vlc_media_player 0.8.6i
Published Aug 20, 2008
Tracked Since Feb 18, 2026