CVE-2011-0531: Input Validation
demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary commands via a crafted MKV (WebM or Matroska) file that triggers memory corruption, related to "class mismatching" and the MKVISID macro.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0531?
CVE-2011-0531 has a high severity due to its potential to cause denial of service and execute arbitrary commands.
How do I fix CVE-2011-0531?
To fix CVE-2011-0531, update VideoLAN VLC media player to version 1.1.7 or later.
What types of attacks are possible with CVE-2011-0531?
CVE-2011-0531 can allow remote attackers to cause a denial of service and execute arbitrary commands via crafted MKV files.
Which versions of VLC are affected by CVE-2011-0531?
Vulnerable versions include VideoLAN VLC media player 1.1.6.1 and earlier, as well as various older versions.
Is CVE-2011-0531 applicable to operating systems?
CVE-2011-0531 primarily affects the VLC media player and is not directly tied to any specific operating system vulnerabilities.