6.8
CVSSv2

CVE-2013-4388

Published: 11/10/2013 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the mp4a packetizer (modules/packetizer/mpeg4audio.c) in VideoLAN VLC Media Player prior to 2.0.8 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

videolan vlc media player

videolan vlc media player 2.0.2

videolan vlc media player 2.0.1

videolan vlc media player 2.0.6

videolan vlc media player 2.0.0

videolan vlc media player 2.0.5

videolan vlc media player 2.0.3

videolan vlc media player 2.0.4

Vendor Advisories

Debian Bug report logs - #726528 vlc: CVE-2013-4388 Package: vlc; Maintainer for vlc is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for vlc is src:vlc (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Wed, 16 Oct 2013 13:18:01 UTC Severity: grave Tags: patch, ...
Multiple buffer overflows have been found in the VideoLAN media player Processing malformed subtitles or movie files could lead to denial of service and potentially the execution of arbitrary code For the stable distribution (wheezy), these problems have been fixed in version 203-5+deb7u1 For the testing distribution (jessie), these problems h ...