CVE-2011-1684: Buffer Overflow
Heap-based buffer overflow in the MP4ReadBoxskcr function in libmp4.c in the MP4 demultiplexer in VideoLAN VLC media player 1.x before 1.1.9 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted MP4 file.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1684?
CVE-2011-1684 is classified as a critical vulnerability that can lead to denial of service or potential remote code execution.
How do I fix CVE-2011-1684?
To fix CVE-2011-1684, upgrade your VLC media player to version 1.1.9 or later.
Which versions of VLC media player are affected by CVE-2011-1684?
CVE-2011-1684 affects VLC media player versions from 1.0.0 to 1.1.8.
What type of attack does CVE-2011-1684 enable?
CVE-2011-1684 enables attackers to exploit a heap-based buffer overflow, potentially leading to application crashes or arbitrary code execution.
Where can I find more information about CVE-2011-1684?
Further details about CVE-2011-1684 can be found in security advisories and vulnerability databases specific to VLC.