6.8
CVSSv2

CVE-2012-3377

Published: 12/07/2012 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in the Ogg_DecodePacket function in the OGG demuxer (modules/demux/ogg.c) in VideoLAN VLC media player prior to 2.0.2 allows remote malicious users to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted OGG file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

videolan vlc media player 0.8.6b

videolan vlc media player 1.1.3

videolan vlc media player 0.7.2

videolan vlc media player 1.1.13

videolan vlc media player 0.8.6g

videolan vlc media player 1.1.7

videolan vlc media player 0.4.3-ac3

videolan vlc media player 0.8.1337

videolan vlc media player 0.5.0

videolan vlc media player 0.8.4a

videolan vlc media player 0.2.62

videolan vlc media player 0.4.0

videolan vlc media player 0.1.99e

videolan vlc media player 0.1.99d

videolan vlc media player 1.0.3

videolan vlc media player 0.8.0

videolan vlc media player 0.1.99g

videolan vlc media player 0.2.70

videolan vlc media player 0.9.0

videolan vlc media player 0.4.3

videolan vlc media player 0.9.4

videolan vlc media player 1.1.4

videolan vlc media player 0.8.5

videolan vlc media player 0.9.9a

videolan vlc media player 0.6.2

videolan vlc media player 0.2.61

videolan vlc media player 0.8.6h

videolan vlc media player 0.9.10

videolan vlc media player 0.2.71

videolan vlc media player 1.1.5

videolan vlc media player 0.2.83

videolan vlc media player 0.8.4

videolan vlc media player 0.2.72

videolan vlc media player 0.8.6

videolan vlc media player 0.2.0

videolan vlc media player 0.3.0

videolan vlc media player 1.1.11

videolan vlc media player 0.4.4

videolan vlc media player 0.2.50

videolan vlc media player 0.8.6c

videolan vlc media player 0.2.80

videolan vlc media player 0.8.6i

videolan vlc media player 0.5.2

videolan vlc media player 0.7.0

videolan vlc media player 1.1.6.1

videolan vlc media player 0.9.1

videolan vlc media player 1.1.10

videolan vlc media player 0.9.8a

videolan vlc media player 0.2.81

videolan vlc media player 1.0.1

videolan vlc media player 0.5.3

videolan vlc media player 1.1.9

videolan vlc media player 0.8.6a

videolan vlc media player 0.2.60

videolan vlc media player 1.1.2

videolan vlc media player 1.0.0

videolan vlc media player 0.4.6

videolan vlc media player 0.9.5

videolan vlc media player 0.6.0

videolan vlc media player 0.2.73

videolan vlc media player 1.0.4

videolan vlc media player 2.0.0

videolan vlc media player 0.2.82

videolan vlc media player 0.1.99a

videolan vlc media player 1.1.0

videolan vlc media player 0.1.99h

videolan vlc media player 0.8.6f

videolan vlc media player 0.4.1

videolan vlc media player 0.2.92

videolan vlc media player 0.2.91

videolan vlc media player 0.5.1

videolan vlc media player 0.4.2

videolan vlc media player 1.0.2

videolan vlc media player 0.9.2

videolan vlc media player 0.1.99b

videolan vlc media player 0.6.1

videolan vlc media player 0.1.99f

videolan vlc media player 0.1.99i

videolan vlc media player 1.1.6

videolan vlc media player 0.8.1

videolan vlc media player 1.1.8

videolan vlc media player 0.9.9

videolan vlc media player

videolan vlc media player 0.8.6e

videolan vlc media player 0.8.6d

videolan vlc media player 1.1.4.1

videolan vlc media player 0.7.1

videolan vlc media player 0.1.99c

videolan vlc media player 1.1.1

videolan vlc media player 0.2.90

videolan vlc media player 0.8.2

videolan vlc media player 0.4.5

videolan vlc media player 1.0.6

videolan vlc media player 1.0.5

videolan vlc media player 0.9.3

videolan vlc media player 0.2.63

videolan vlc media player 0.9.6

videolan vlc media player 1.1.10.1

videolan vlc media player 0.3.1

Vendor Advisories

Debian Bug report logs - #680665 vlc: CVE-2012-3377: Ogg demuxer heap buffer overflow Package: vlc; Maintainer for vlc is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for vlc is src:vlc (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Sat, 7 Jul 2012 21:06:01 UTC Sev ...