PT-2011-1217 · Videolan · Vlc Media Player

Rocco Calvi

·

Published

2011-06-03

·

Updated

2017-09-19

·

CVE-2011-2194

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VLC media player versions 0.8.5 through 1.1.9
Description The issue is related to an integer overflow in the XSPF playlist parser, which can be exploited by remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a heap-based buffer overflow.
Recommendations For versions 0.8.5 through 1.1.9, consider disabling the XSPF playlist parser as a temporary workaround until a patch is available. Restrict access to the XSPF parser to minimize the risk of exploitation.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03977
CVE-2011-2194
DSA-2257-1

Affected Products

Vlc Media Player