![]() |
Inicial ▼ Bookkeeping
Online ▼ Auditorias ▼
DNS
Administrado ▼
Acerca de DNS
Ordenar/Renovar
Preguntas Frecuentes
AUP
Dynamic DNS Clients
Configurar Dominios Dynamic DNS Update Password Monitoreo
de Redes ▼
Enterprise
Avanzado
Estándarr
Prueba
Preguntas Frecuentes
Resumen de Precio/Funciones
Ordenar
Muestras
Configure/Status Alert Profiles | ||
ID de Prueba: | 1.3.6.1.4.1.25623.1.0.902342 |
Categoría: | Buffer overflow |
Título: | VLC Media Player USF and Text Subtitles Decoders BOF Vulnerabilities - Linux |
Resumen: | VLC Media Player is prone to buffer overflow vulnerabilities. |
Descripción: | Summary: VLC Media Player is prone to buffer overflow vulnerabilities. Vulnerability Insight: The flaws are caused by buffer overflow errors in the 'StripTags()' function within the USF and Text subtitles decoders 'modules/codec/subtitles/subsdec.c' and 'modules/codec/subtitles/subsusf.c' when processing malformed data. Vulnerability Impact: Successful exploitation could allow attackers to crash an affected application or execute arbitrary by convincing a user to open a malicious media file. Affected Software/OS: VLC media player version 1.x before 1.1.6-rc Solution: Upgrade to the VLC media player version 1.1.6-rc or later. CVSS Score: 6.8 CVSS Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P |
Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-2011-0522 BugTraq ID: 46008 http://www.securityfocus.com/bid/46008 http://www.exploit-db.com/exploits/16108 http://www.openwall.com/lists/oss-security/2011/01/25/7 http://www.openwall.com/lists/oss-security/2011/01/25/9 http://mailman.videolan.org/pipermail/vlc-devel/2011-January/078607.html http://mailman.videolan.org/pipermail/vlc-devel/2011-January/078614.html https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12414 http://securityreason.com/securityalert/8064 http://www.vupen.com/english/advisories/2011/0225 XForce ISS Database: vlcmediaplayer-usf-bo(65029) https://exchange.xforce.ibmcloud.com/vulnerabilities/65029 |
Copyright | Copyright (C) 2011 Greenbone AG |
Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |