PT-2014-2076 · Videolan · Vlc Media Player

Alex Legler

·

Published

2014-12-26

·

Updated

2014-12-29

·

CVE-2010-1444

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions VideoLAN VLC media player versions prior to 1.0.6
Description The issue concerns the ZIP archive decompressor in the VideoLAN VLC media player, which allows remote attackers to cause a denial of service, resulting in invalid memory access and application crash, or possibly execute arbitrary code via a crafted archive.
Recommendations For versions prior to 1.0.6, update to version 1.0.6 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the ZIP archive decompressor until a patch is available. Restrict access to potentially malicious ZIP archives to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1444

Affected Products

Vlc Media Player