9.3
CVSSv2

CVE-2011-0531

Published: 07/02/2011 Updated: 07/11/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and previous versions allows remote malicious users to cause a denial of service (crash) and execute arbitrary commands via a crafted MKV (WebM or Matroska) file that triggers memory corruption, related to "class mismatching" and the MKV_IS_ID macro.

Vulnerable Product Search on Vulmon Subscribe to Product

videolan vlc media player 1.1.3

videolan vlc media player 0.7.2

videolan vlc media player 0.5.0

videolan vlc media player 0.2.62

videolan vlc media player 0.4.0

videolan vlc media player 0.1.99e

videolan vlc media player 1.0.3

videolan vlc media player 0.8.0

videolan vlc media player 0.1.99g

videolan vlc media player 0.2.70

videolan vlc media player 0.4.3

videolan vlc media player 0.9.4

videolan vlc media player 1.1.4

videolan vlc media player 0.8.5

videolan vlc media player 0.6.2

videolan vlc media player 0.2.61

videolan vlc media player 0.9.10

videolan vlc media player 0.2.71

videolan vlc media player

videolan vlc media player 1.1.5

videolan vlc media player 0.2.83

videolan vlc media player 0.8.4

videolan vlc media player 0.2.72

videolan vlc media player 0.8.6

videolan vlc media player 0.2.0

videolan vlc media player 0.3.0

videolan vlc media player 0.4.4

videolan vlc media player 0.2.80

videolan vlc media player 0.5.2

videolan vlc media player 0.7.0

videolan vlc media player 0.9.8a

videolan vlc media player 0.2.81

videolan vlc media player 1.0.1

videolan vlc media player 0.5.3

videolan vlc media player 0.2.60

videolan vlc media player 1.1.2

videolan vlc media player 1.0.0

videolan vlc media player 0.4.6

videolan vlc media player 0.9.5

videolan vlc media player 0.6.0

videolan vlc media player 0.2.73

videolan vlc media player 1.0.4

videolan vlc media player 0.2.82

videolan vlc media player 1.1.0

videolan vlc media player 0.1.99h

videolan vlc media player 0.4.1

videolan vlc media player 0.2.92

videolan vlc media player 0.2.91

videolan vlc media player 0.5.1

videolan vlc media player 0.4.2

videolan vlc media player 1.0.2

videolan vlc media player 0.9.2

videolan vlc media player 0.1.99b

videolan vlc media player 0.6.1

videolan vlc media player 0.1.99f

videolan vlc media player 0.1.99i

videolan vlc media player 1.1.6

videolan vlc media player 0.8.1

videolan vlc media player 0.9.9

videolan vlc media player 1.1.1

videolan vlc media player 0.2.90

videolan vlc media player 0.8.2

videolan vlc media player 0.4.5

videolan vlc media player 1.0.6

videolan vlc media player 1.0.5

videolan vlc media player 0.9.3

videolan vlc media player 0.2.63

videolan vlc media player 0.9.6

videolan vlc media player 0.3.1

Vendor Advisories

Dan Rosenberg discovered that insufficient input validation in VLC's processing of Matroska/WebM containers could lead to the execution of arbitrary code For the stable distribution (squeeze), this problem has been fixed in version 113-1squeeze3 The version of vlc in the oldstable distribution (lenny) is affected by further issues and will be a ...

Exploits

## # $Id: vlc_webmrb 11725 2011-02-08 18:22:36Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' class Metasp ...