9.3
CVSSv2

CVE-2011-2194

Published: 24/06/2011 Updated: 19/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer overflow in the XSPF playlist parser in VideoLAN VLC media player 0.8.5 up to and including 1.1.9 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a heap-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

videolan vlc media player 0.8.6b

videolan vlc media player 0.8.6i

videolan vlc media player 0.9.0

videolan vlc media player 0.9.9a

videolan vlc media player 0.9.8a

videolan vlc media player 0.9.5

videolan vlc media player 1.0.1

videolan vlc media player 1.1.0

videolan vlc media player 1.1.7

videolan vlc media player 1.1.8

videolan vlc media player 0.8.5

videolan vlc media player 0.8.6

videolan vlc media player 0.8.6f

videolan vlc media player 0.9.9

videolan vlc media player 0.9.4

videolan vlc media player 0.9.3

videolan vlc media player 1.0.6

videolan vlc media player 1.0.3

videolan vlc media player 1.1.3

videolan vlc media player 1.1.4

videolan vlc media player 0.8.6d

videolan vlc media player 0.8.6a

videolan vlc media player 0.8.6c

videolan vlc media player 0.8.6e

videolan vlc media player 0.9.6

videolan vlc media player 0.9.10

videolan vlc media player 1.0.0

videolan vlc media player 1.0.2

videolan vlc media player 1.1.5

videolan vlc media player 0.8.6h

videolan vlc media player 0.8.6g

videolan vlc media player 0.9.1

videolan vlc media player 0.9.2

videolan vlc media player 1.0.4

videolan vlc media player 1.0.5

videolan vlc media player 1.1.1

videolan vlc media player 1.1.2

videolan vlc media player 1.1.4.1

videolan vlc media player 1.1.9

videolan vlc media player 1.1.6

Vendor Advisories

Rocco Calvi discovered that the XSPF playlist parser of VLC, a multimedia player and streamer, is prone to an integer overflow resulting in a heap-based buffer overflow This might allow an attacker to execute arbitrary code by tricking a victim into opening a specially crafted file The oldstable distribution (lenny) is not affected by this proble ...

Exploits

TITLE VLC Media Player XSPF Local File Integer overflow in XSPF playlist parser AFFECTED VERSIONS VLC media player 119 down to 085 VENDOR VideoLAN Organisation CLASS Denial of Service (DoS) RESOURCES wwwvideolanorg/security/sa1104html PRODUCT DESCRIPTION VLC is a free and open source cross-platform multimedia playe ...