Unrated severityNVD Advisory· Published Jan 17, 2008· Updated Apr 23, 2026
CVE-2007-6683
CVE-2007-6683
Description
The browser plugin in VideoLAN VLC 0.8.6d allows remote attackers to overwrite arbitrary files via (1) the :demuxdump-file option in a filename in a playlist, or (2) a EXTVLCOPT statement in an MP3 file, possibly an argument injection vulnerability.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- mailman.videolan.org/pipermail/vlc-devel/2007-December/037726.htmlnvdExploit
- osvdb.org/42205nvd
- osvdb.org/42206nvd
- secunia.com/advisories/29284nvd
- secunia.com/advisories/29766nvd
- www.debian.org/security/2008/dsa-1543nvd
- www.gentoo.org/security/en/glsa/glsa-200803-13.xmlnvd
- www.securityfocus.com/bid/28712nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14619nvd
- trac.videolan.org/vlc/changeset/23197nvd
- trac.videolan.org/vlc/ticket/1371nvd
News mentions
0No linked articles in our index yet.