DEBIAN-CVE-2008-4686

Source
https://security-tracker.debian.org/tracker/CVE-2008-4686
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-4686.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2008-4686
Upstream
Downstream
Published
2008-10-22T18:00:01Z
Modified
2026-09-01T20:02:55Z
Summary
[none]
Details

Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote attackers to execute arbitrary code via a crafted .ty file, a different vulnerability than CVE-2008-4654.

References

Affected packages

Debian:12 / vlc

Package

Name
vlc
Purl
pkg:deb/debian/vlc?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.8.6.h-4.1

Ecosystem specific

{
    "urgency": "medium"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-4686.json"

Debian:13 / vlc

Package

Name
vlc
Purl
pkg:deb/debian/vlc?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.8.6.h-4.1

Ecosystem specific

{
    "urgency": "medium"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-4686.json"

Debian:14 / vlc

Package

Name
vlc
Purl
pkg:deb/debian/vlc?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.8.6.h-4.1

Ecosystem specific

{
    "urgency": "medium"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-4686.json"