CVE-2010-1443: Null Pointer Dereference
The parsetracknode function in modules/demux/playlist/xspf.c in the XSPF playlist parser in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty location element in an XML Shareable Playlist Format (XSPF) document.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1443?
CVE-2010-1443 is classified as a denial-of-service vulnerability that can cause application crashes.
How do I fix CVE-2010-1443?
To fix CVE-2010-1443, upgrade to VLC media player version 1.0.6 or later.
Which versions of VLC media player are affected by CVE-2010-1443?
CVE-2010-1443 affects VLC media player versions 0.5.0 through 1.0.5.
What kind of exploit does CVE-2010-1443 allow?
CVE-2010-1443 allows remote attackers to cause a denial of service via an empty location element in an XSPF file.
Is there a workaround for CVE-2010-1443 if I can't upgrade VLC?
There is no official workaround for CVE-2010-1443; the best mitigation is to upgrade VLC to a safe version.