{"id":"CVE-2008-2147","details":"Untrusted search path vulnerability in VideoLAN VLC before 0.9.0 allows local users to execute arbitrary code via a malicious library under the modules/ or plugins/ subdirectories of the current working directory.","modified":"2026-01-27T04:08:43.265379Z","published":"2008-05-12T20:20:00Z","withdrawn":"2026-01-27T04:08:43.265379Z","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/31317"},{"type":"ADVISORY","url":"http://security.gentoo.org/glsa/glsa-200807-13.xml"},{"type":"WEB","url":"http://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=c7cef4fdd8dd72ce0a45be3cda8ba98df5e83181"},{"type":"WEB","url":"http://trac.videolan.org/vlc/ticket/1578"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42377"}],"schema_version":"1.7.3"}