PT-2014-2075 · Videolan · Vlc Media Player

Alex Legler

·

Published

2014-12-26

·

Updated

2014-12-29

·

CVE-2010-1443

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions VLC media player versions prior to 1.0.6
Description The issue allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and application crash. This can be achieved through an empty location element in an XML Shareable Playlist Format (XSPF) document. The parse track node function in the XSPF playlist parser is affected.
Recommendations For versions prior to 1.0.6, update to version 1.0.6 or later to resolve the issue. As a temporary workaround, consider avoiding the use of empty location elements in XSPF documents to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-1443

Affected Products

Vlc Media Player