Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.801726
Categoría:Buffer overflow
Título:VLC Media Player 'CDG decoder' Multiple Buffer Overflow Vulnerabilities - Windows
Resumen:VLC Media Player is prone to multiple buffer overflow vulnerabilities.
Descripción:Summary:
VLC Media Player is prone to multiple buffer overflow vulnerabilities.

Vulnerability Insight:
The flaws are due to an array indexing errors in the 'DecodeTileBlock()'
and 'DecodeScroll()' [modules/codec/cdg.c] functions within the CDG decoder
module when processing malformed data.

Vulnerability Impact:
Successful exploitation could allow attackers to crash the affected
application, or execute arbitrary code by convincing a user to open a
malicious CD+G (CD+Graphics) media file or visit a specially crafted web
page.

Affected Software/OS:
VLC media player version prior to 1.1.6 on Windows.

Solution:
Upgrade to the VLC media player version 1.1.6 or later.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-0021
BugTraq ID: 45927
http://www.securityfocus.com/bid/45927
http://openwall.com/lists/oss-security/2011/01/19/6
http://openwall.com/lists/oss-security/2011/01/20/3
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12460
http://www.vupen.com/english/advisories/2011/0185
XForce ISS Database: vlcmediaplayer-cdg-code-execution(64879)
https://exchange.xforce.ibmcloud.com/vulnerabilities/64879
CopyrightCopyright (C) 2011 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.