CVE-2010-1444: Buffer Overflow
Published Dec 26, 2014
·Updated
The ZIP archive decompressor in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly execute arbitrary code via a crafted archive.
Affected Software
44 affected components
Videolan VLC Media Player<=1.0.5
Videolan VLC Media Player=0.5.0
Videolan VLC Media Player=0.5.1
Videolan VLC Media Player=0.5.2
Videolan VLC Media Player=0.5.3
Videolan VLC Media Player=0.6.0
Videolan VLC Media Player=0.6.1
Videolan VLC Media Player=0.6.2
Videolan VLC Media Player=0.7.0
Videolan VLC Media Player=0.7.1
Videolan VLC Media Player=0.7.2
Videolan VLC Media Player=0.8.0
Videolan VLC Media Player=0.8.1
Videolan VLC Media Player=0.8.2
Videolan VLC Media Player=0.8.4
Videolan VLC Media Player=0.8.4a
Videolan VLC Media Player=0.8.5
Videolan VLC Media Player=0.8.6
Videolan VLC Media Player=0.8.6a
Videolan VLC Media Player=0.8.6b
Videolan VLC Media Player=0.8.6c
Videolan VLC Media Player=0.8.6d
Videolan VLC Media Player=0.8.6e
Videolan VLC Media Player=0.8.6f
Videolan VLC Media Player=0.8.6g
Videolan VLC Media Player=0.8.6h
Videolan VLC Media Player=0.8.6i
Videolan VLC Media Player=0.8.1337
Videolan VLC Media Player=0.9.0
Videolan VLC Media Player=0.9.1
Videolan VLC Media Player=0.9.2
Videolan VLC Media Player=0.9.3
Videolan VLC Media Player=0.9.4
Videolan VLC Media Player=0.9.5
Videolan VLC Media Player=0.9.6
Videolan VLC Media Player=0.9.8a
Videolan VLC Media Player=0.9.9
Videolan VLC Media Player=0.9.9a
Videolan VLC Media Player=0.9.10
Videolan VLC Media Player=1.0.0
Videolan VLC Media Player=1.0.1
Videolan VLC Media Player=1.0.2
Videolan VLC Media Player=1.0.3
Videolan VLC Media Player=1.0.4
Event History
Dec 26, 2014
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-1444?
CVE-2010-1444 has a medium severity level due to its potential to cause denial of service or arbitrary code execution.
2
How do I fix CVE-2010-1444?
To fix CVE-2010-1444, you should update VideoLAN VLC media player to version 1.0.6 or later.
3
What versions of VLC media player are affected by CVE-2010-1444?
CVE-2010-1444 affects VideoLAN VLC media player versions prior to 1.0.6.
4
Can CVE-2010-1444 be exploited remotely?
Yes, CVE-2010-1444 can be exploited remotely through a crafted ZIP archive.
5
What are the consequences of CVE-2010-1444?
Consequences of CVE-2010-1444 include invalid memory access leading to application crashes or possible arbitrary code execution.