Unrated severityNVD Advisory· Published Oct 22, 2008· Updated Apr 23, 2026
CVE-2008-4654
CVE-2008-4654
Description
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player 0.9.0 through 0.9.4 allows remote attackers to execute arbitrary code via a TiVo TY media file with a header containing a crafted size value.
Affected products
5cpe:2.3:a:videolan:vlc_media_player:0.9:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:videolan:vlc_media_player:0.9:*:*:*:*:*:*:*
- cpe:2.3:a:videolan:vlc_media_player:0.9.1:*:*:*:*:*:*:*
- cpe:2.3:a:videolan:vlc_media_player:0.9.2:*:*:*:*:*:*:*
- cpe:2.3:a:videolan:vlc_media_player:0.9.3:*:*:*:*:*:*:*
- cpe:2.3:a:videolan:vlc_media_player:0.9.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- www.trapkit.de/advisories/TKADV2008-010.txtnvdExploit
- secunia.com/advisories/32339nvdVendor Advisory
- www.videolan.org/security/sa0809.htmlnvdVendor Advisory
- bugs.debian.org/cgi-bin/bugreport.cginvd
- securityreason.com/securityalert/4460nvd
- www.openwall.com/lists/oss-security/2008/10/19/2nvd
- www.securityfocus.com/archive/1/497587/100/0/threadednvd
- www.securityfocus.com/bid/31813nvd
- www.vupen.com/english/advisories/2008/2856nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/45960nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14803nvd
News mentions
0No linked articles in our index yet.