VLC Media Player TiVo Demuxer Remote Heap-Based Buffer Overflow Vulnerability
BID:51231
Info
VLC Media Player TiVo Demuxer Remote Heap-Based Buffer Overflow Vulnerability
| Bugtraq ID: | 51231 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2012-0023 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 02 2012 12:00AM |
| Updated: | Mar 19 2015 09:45AM |
| Credit: | Clement Lecigne |
| Vulnerable: |
VideoLAN VLC media player 1.1.12 VideoLAN VLC media player 1.1.9 VideoLAN VLC media player 1.1.8 VideoLAN VLC media player 1.1.7 VideoLAN VLC media player 1.1.6 1 VideoLAN VLC media player 1.1.4 VideoLAN VLC media player 1.1.3 VideoLAN VLC media player 1.1.2 VideoLAN VLC media player 1.1.1 VideoLAN VLC media player 1.1 VideoLAN VLC media player 1.0.6 VideoLAN VLC media player 1.0.5 VideoLAN VLC media player 1.0.3 VideoLAN VLC media player 1.0.2 VideoLAN VLC media player 1.0.1 VideoLAN VLC media player 1.0 VideoLAN VLC media player 0.9.9 VideoLAN VLC media player 0.9.7 VideoLAN VLC media player 0.9.6 VideoLAN VLC media player 0.9.5 VideoLAN VLC media player 0.9.4 VideoLAN VLC media player 0.9.3 VideoLAN VLC media player 0.9.2 VideoLAN VLC media player 0.9.1 VideoLAN VLC media player 0.9 VideoLAN VLC media player 1.1.6 VideoLAN VLC media player 1.1.5 VideoLAN VLC media player 1.1.3 VideoLAN VLC media player 1.1.2 VideoLAN VLC media player 1.1.11 VideoLAN VLC media player 1.1.10 VideoLAN VLC media player 1.1.1 VideoLAN VLC media player 1.1.0 VideoLAN VLC media player 1.0.4 VideoLAN VLC media player 0.9.8a Gentoo Linux |
| Not Vulnerable: |
VideoLAN VLC media player 1.1.13 |
Discussion
VLC Media Player TiVo Demuxer Remote Heap-Based Buffer Overflow Vulnerability
VLC media player is prone to a heap-based buffer-overflow vulnerability that affects the TiVo demuxer.
Successful exploits can allow attackers to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
VLC media player versions 0.9.0 through 1.1.12 are vulnerable; other versions may also be affected.
VLC media player is prone to a heap-based buffer-overflow vulnerability that affects the TiVo demuxer.
Successful exploits can allow attackers to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
VLC media player versions 0.9.0 through 1.1.12 are vulnerable; other versions may also be affected.
Solution / Fix
VLC Media Player TiVo Demuxer Remote Heap-Based Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
VLC Media Player TiVo Demuxer Remote Heap-Based Buffer Overflow Vulnerability
References:
References:
- Security Advisory 1108 Buffer overflow in VLC TiVo demuxer (VideoLAN)
- VLC Homepage (VideoLAN)