HIGH
VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly execute arbitrary code via a crafted byte stream to the (1) AVI, (2) ASF, or (3) Matroska (aka MKV) demuxer
Published Dec 26, 2014
7.5
HIGHCVSS 2.0
EPSS 3.01%
Description
VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly execute arbitrary code via a crafted byte stream to the (1) AVI, (2) ASF, or (3) Matroska (aka MKV) demuxer.
Affected products
No data.
OR
- ≤ 1.0.5
- 0.5.0
- 0.5.1
- 0.5.2
- 0.5.3
- 0.6.0
- 0.6.1
- 0.6.2
- 0.7.0
- 0.7.1
- 0.7.2
- 0.8.0
- 0.8.1
- 0.8.2
- 0.8.4
- 0.8.4a
- 0.8.5
- 0.8.6
- 0.8.6a
- 0.8.6b
- 0.8.6c
- 0.8.6d
- 0.8.6e
- 0.8.6f
- 0.8.6g
- 0.8.6h
- 0.8.6i
- 0.8.1337
- 0.9.0
- 0.9.1
- 0.9.2
- 0.9.3
- 0.9.4
- 0.9.5
- 0.9.6
- 0.9.8a
- 0.9.9
- 0.9.9a
- 0.9.10
- 1.0.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- http://openwall.com/lists/oss-security/2010/04/28/4 mailing-listx_refsource_MLIST
- http://www.videolan.org/security/sa1003.html x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://openwall.com/lists/oss-security/2010/04/28/4 | mailing-listx_refsource_MLIST | |
| http://www.videolan.org/security/sa1003.html | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 26, 2014
Updated Aug 7, 2024
Reserved Apr 15, 2010
Link CVE-2010-1442
CISA Vulnrichment
Updated n/a