CVE-2007-3121

NameCVE-2007-3121
DescriptionBuffer overflow in the CCdecode function in contrib/ntsc-cc.c in the zvbi-ntsc-cc tool in Zapping VBI Library (ZVBI) before 0.2.25 allows attackers to cause a denial of service (application crash) and possibly execute arbitrary code via long data during a reception error. NOTE: some of these details are obtained from third party information.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs429221

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
zvbi (PTS)bullseye0.2.35-18fixed
bookworm0.2.41-1fixed
sid, trixie0.2.43-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
zvbisource(unstable)0.2.25-1unimportant429221

Notes

Only exploitable through malformed closed captions
Malicious TV networks have more subtle methods to control people...

Search for package or bug name: Reporting problems