4.3
CVSSv2

CVE-2012-5470

Published: 26/10/2012 Updated: 19/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote malicious users to cause a denial of service (application crash) via a crafted PNG file.

Vulnerable Product Search on Vulmon Subscribe to Product

videolan vlc media player 2.0.3

Vendor Advisories

Debian Bug report logs - #692130 vlc: CVE-2012-5470 Package: vlc; Maintainer for vlc is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for vlc is src:vlc (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Fri, 2 Nov 2012 14:21:02 UTC Severity: grave Tags: securi ...

Exploits

#!/usr/bin/perl # VLC Player 203 <= ReadAV Arbitrary Code Execution # Author: Jean Pascal Pereira <pereira@secbizde> # Vendor URI: wwwvideolanorg/vlc/ # Vendor Description: # VLC is a free and open source cross-platform multimedia player # and framework that plays most multimedia files as well as DVD, # Audio CD, VCD, a ...