LWN.net Logo

vlc: arbitrary code execution

Package(s):vlc vlc-firefox CVE #(s):CVE-2011-0021
Created:February 14, 2011 Updated:February 16, 2011
Description: From the Pardus advisory:

Multiple heap-based buffer overflows in cdg.c in the CDG decoder in VideoLAN VLC Media Player before 1.1.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted CDG video.

Alerts:
Pardus 2011-39 2011-02-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds