VLC Media Player ASF File Handling Buffer Overflow Vulnerability
BID:57333
Info
VLC Media Player ASF File Handling Buffer Overflow Vulnerability
| Bugtraq ID: | 57333 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2013-1954 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2013 12:00AM |
| Updated: | Mar 19 2015 09:44AM |
| Credit: | Debasish Mandal |
| Vulnerable: |
VideoLAN VLC media player 2.0.1 VideoLAN VLC media player 2.0 VideoLAN VLC media player 1.2 VideoLAN VLC media player 1.1.13 VideoLAN VLC media player 1.1.12 VideoLAN VLC media player 1.1.11 VideoLAN VLC media player 1.1.9 VideoLAN VLC media player 1.1.8 VideoLAN VLC media player 1.1.7 VideoLAN VLC media player 1.1.6 1 VideoLAN VLC media player 1.1.4 VideoLAN VLC media player 1.1.3 VideoLAN VLC media player 1.1.2 VideoLAN VLC media player 1.1.1 VideoLAN VLC media player 1.1 VideoLAN VLC media player 1.0.6 VideoLAN VLC media player 1.0.5 VideoLAN VLC media player 1.0.3 VideoLAN VLC media player 1.0.2 VideoLAN VLC media player 1.0.1 VideoLAN VLC media player 1.0 VideoLAN VLC media player 1.1.6 VideoLAN VLC media player 1.1.5 VideoLAN VLC media player 1.1.3 VideoLAN VLC media player 1.1.2 VideoLAN VLC media player 1.1.11 VideoLAN VLC media player 1.1.10 VideoLAN VLC media player 1.1.1 VideoLAN VLC media player 1.1.0 VideoLAN VLC media player 1.0.4 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
VLC Media Player ASF File Handling Buffer Overflow Vulnerability
VLC media player is prone to a denial-of-service vulnerability because the application fails to sufficiently validate user-supplied input.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
VLC Media Player 2.0.5 and prior versions are vulnerable.
VLC media player is prone to a denial-of-service vulnerability because the application fails to sufficiently validate user-supplied input.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
VLC Media Player 2.0.5 and prior versions are vulnerable.
Exploit / POC
VLC Media Player ASF File Handling Buffer Overflow Vulnerability
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
Solution / Fix
VLC Media Player ASF File Handling Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
VLC Media Player ASF File Handling Buffer Overflow Vulnerability
References:
References:
- Security Advisory 1302 (VideoLAN)
- Security Issue While Parsing A Specially Crafted ASF file (VideoLAN)
- VLC Homepage (VideoLAN)