4.3
CVSSv2

CVE-2014-1684

Published: 03/03/2014 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The ASF_ReadObject_file_properties function in modules/demux/asf/libasf.c in the ASF Demuxer in VideoLAN VLC Media Player prior to 2.1.3 allows remote malicious users to cause a denial of service (divide-by-zero error and crash) via a zero minimum and maximum data packet size in an ASF file.

Vulnerable Product Search on Vulmon Subscribe to Product

videolan vlc media player 1.1.3

videolan vlc media player 1.1.13

videolan vlc media player 1.1.7

videolan vlc media player

videolan vlc media player 2.0.7

videolan vlc media player 1.0.3

videolan vlc media player 2.1.0

videolan vlc media player 2.0.2

videolan vlc media player 2.1.1

videolan vlc media player 1.1.4

videolan vlc media player 2.0.1

videolan vlc media player 1.1.5

videolan vlc media player 1.1.11

videolan vlc media player 1.1.12

videolan vlc media player 2.0.9

videolan vlc media player 1.1.6.1

videolan vlc media player 1.1.10

videolan vlc media player 2.0.8

videolan vlc media player 1.0.1

videolan vlc media player 1.1.9

videolan vlc media player 2.0.6

videolan vlc media player 1.1.2

videolan vlc media player 1.0.0

videolan vlc media player 1.0.4

videolan vlc media player 2.0.0

videolan vlc media player 1.1.0

videolan vlc media player 1.0.2

videolan vlc media player 2.0.5

videolan vlc media player 2.0.3

videolan vlc media player 1.1.6

videolan vlc media player 1.1.8

videolan vlc media player 2.0.4

videolan vlc media player 1.1.4.1

videolan vlc media player 1.1.1

videolan vlc media player 1.0.6

videolan vlc media player 1.0.5

videolan vlc media player 1.1.10.1

Vendor Advisories

Debian Bug report logs - #743033 vlc: CVE-2014-1684: crafted ASF file handling integer divide-by-zero DoS Package: vlc; Maintainer for vlc is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for vlc is src:vlc (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Sun, 30 Mar 20 ...

Exploits

#!/usr/bin/python # VLC Media Player up to 212 DOS POC Integer Division By zero in ASF Demuxer # VLC Media Player is prone to DOS utilizing a division by zero error if minimium data packet size # is equal to zero this was tested on windows XP sp3 and affects all versions of vlc till latest 212 # to run this script you need to install python bi ...