CVE-2010-3907: Buffer Overflow
Multiple integer overflows in real.c in the Real demuxer plugin in VideoLAN VLC Media Player before 1.1.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a zero isubpackets value in a Real Media file, leading to a heap-based buffer overflow.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3907?
CVE-2010-3907 has a severity rating that indicates it can lead to application crashes or potentially allow execution of arbitrary code.
How do I fix CVE-2010-3907?
To mitigate CVE-2010-3907, update VLC Media Player to version 1.1.6 or later.
What versions of VLC Media Player are affected by CVE-2010-3907?
Vulnerable versions include all versions of VLC Media Player prior to 1.1.6.
What type of vulnerability is CVE-2010-3907?
CVE-2010-3907 is categorized as an integer overflow vulnerability affecting the Real demuxer plugin.
Can CVE-2010-3907 be exploited remotely?
Yes, CVE-2010-3907 can potentially be exploited by remote attackers through specially crafted Real Media files.