First published: Thu Jul 16 2009(Updated: )
Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.9, when running on Microsoft Windows, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long smb URI in a playlist file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VideoLAN VLC media player | =0.9.9 | |
Microsoft Windows | ||
VLC media player | =0.9.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2009-2484 is considered critical due to its potential to cause application crashes and execute arbitrary code.
To fix CVE-2009-2484, update VLC media player to a version newer than 0.9.9 where the vulnerability has been addressed.
CVE-2009-2484 affects VideoLAN VLC media player version 0.9.9 running on Microsoft Windows.
Yes, CVE-2009-2484 can lead to a denial of service by crashing the VLC media player through a stack-based buffer overflow.
CVE-2009-2484 is a stack-based buffer overflow vulnerability found in the Win32AddConnection function of VLC media player.