CVE-2009-1045: Input Validation
Published Mar 23, 2009
·Updated
requests/status.xml in VLC 0.9.8a allows remote attackers to cause a denial of service (stack consumption and crash) via a long input argument in an inplay action.
Affected Software
1 affected component
Videolan VLC Media Player=0.9.8a
Event History
Mar 23, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-1045?
CVE-2009-1045 is classified as a denial of service vulnerability allowing for potential crashes of VLC media player.
2
How do I fix CVE-2009-1045?
To mitigate CVE-2009-1045, users should upgrade to a newer version of VLC media player that is unaffected by this vulnerability.
3
Who is affected by CVE-2009-1045?
CVE-2009-1045 affects users running VLC media player version 0.9.8a.
4
What kind of attack is associated with CVE-2009-1045?
CVE-2009-1045 can be exploited by remote attackers via long input arguments in the in_play action.
5
Is there any workaround for CVE-2009-1045?
There are no specific workarounds for CVE-2009-1045; updating to a secure version is the recommended solution.