LWN.net Logo

vlc: arbitrary command execution

Package(s):vlc CVE #(s):CVE-2011-0531
Created:February 11, 2011 Updated:April 7, 2011
Description: From the CVE entry:

demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary commands via a crafted MKV (WebM or Matroska) file that triggers memory corruption, related to "class mismatching" and the MKV_IS_ID macro.

Alerts:
Debian DSA-2211-1 2011-04-06
Pardus 2011-39 2011-02-14
Debian DSA-2159-1 2011-02-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds