LWN.net Logo

vlc: arbitrary code execution

Package(s):vlc CVE #(s):CVE-2010-3275 CVE-2010-3276
Created:April 7, 2011 Updated:April 13, 2011
Description: From the CVE entries:

libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an AMV file, related to a "dangling pointer vulnerability." (CVE-2010-3275)

libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an NSV file. (CVE-2010-3276)

Alerts:
Debian DSA-2211-1 2011-04-06

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds