PT-2011-1217 · Videolan · Vlc Media Player

Rocco Calvi

·

Publicado

2011-06-03

·

Atualizado

2017-09-19

·

CVE-2011-2194

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VLC media player versions 0.8.5 through 1.1.9
Description The issue is related to an integer overflow in the XSPF playlist parser, which can be exploited by remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a heap-based buffer overflow.
Recommendations For versions 0.8.5 through 1.1.9, consider disabling the XSPF playlist parser as a temporary workaround until a patch is available. Restrict access to the XSPF parser to minimize the risk of exploitation.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-03977
CVE-2011-2194
DSA-2257-1

Produtos afetados

Vlc Media Player