PT-2011-2425 · Videolan · Vlc Media Player

Dan Rosenberg

·

Publicado

2011-02-07

·

Atualizado

2017-09-19

·

CVE-2011-0531

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VLC media player version 1.1.6.1 and earlier
Description The issue allows remote attackers to cause a denial of service (crash) and potentially execute arbitrary commands via a crafted MKV (WebM or Matroska) file. This is related to "class mismatching" and the MKV IS ID macro, which can trigger memory corruption.
Recommendations For VLC media player version 1.1.6.1 and earlier, consider updating to a newer version to resolve the issue. As a temporary workaround, avoid using the MKV demuxer plugin until a patch is available. Restrict access to crafted MKV files to minimize the risk of exploitation.

Exploit

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-0531
DSA-2159-1

Produtos afetados

Vlc Media Player