← Back

CVE-2011-3623

nvd nist
Published: Dec 26, 2014Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Multiple stack-based buffer overflows in VideoLAN VLC media player before 1.0.2 allow remote attackers to execute arbitrary code via (1) a crafted ASF file, related to the ASF_ObjectDumpDebug function in modules/demux/asf/libasf.c; (2) a crafted AVI file, related to the AVI_ChunkDumpDebug_level function in modules/demux/avi/libavi.c; or (3) a crafted MP4 file, related to the __MP4_BoxDumpStructure function in modules/demux/mp4/libmp4.c.

Affected (40)

1 product
Vlc Media Player
Configuration A
40 vulnerable
Vulnerable SoftwareAffected Versions
Videolan
Up to 1.0.1
Version 0.5.0
Version 0.5.1
Version 0.5.2
Version 0.5.3
Version 0.6.0
Version 0.6.1
Version 0.6.2
Version 0.7.0
Version 0.7.1
Version 0.7.2
Version 0.8.0
Version 0.8.1337
Version 0.8.1
Version 0.8.2
Version 0.8.4
Version 0.8.4a
Version 0.8.5
Version 0.8.6
Version 0.8.6a
Version 0.8.6b
Version 0.8.6c
Version 0.8.6d
Version 0.8.6e
Version 0.8.6f
Version 0.8.6g
Version 0.8.6h
Version 0.8.6i
Version 0.9.0
Version 0.9.10
Version 0.9.1
Version 0.9.2
Version 0.9.3
Version 0.9.4
Version 0.9.5
Version 0.9.6
Version 0.9.8a
Version 0.9.9
Version 0.9.9a
Version 1.0.0

Timeline

No history available yet.