CVE-2011-2587: Buffer Overflow
Published Jul 27, 2011
·Updated
Heap-based buffer overflow in the DemuxAudioSipr function in real.c in the RealMedia demuxer in VideoLAN VLC media player 1.1.x before 1.1.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Real Media file.
Affected Software
14 affected components
Videolan VLC Media Player=1.1.0
Videolan VLC Media Player=1.1.1
Videolan VLC Media Player=1.1.2
Videolan VLC Media Player=1.1.3
Videolan VLC Media Player=1.1.4
Videolan VLC Media Player=1.1.4.1
Videolan VLC Media Player=1.1.5
Videolan VLC Media Player=1.1.6
Videolan VLC Media Player=1.1.6.1
Videolan VLC Media Player=1.1.7
Videolan VLC Media Player=1.1.8
Videolan VLC Media Player=1.1.9
Videolan VLC Media Player=1.1.10
Videolan VLC Media Player=1.1.10.1
Remediation
Patch Available
Event History
Jul 27, 2011
CVE Published
via MITRE·01:29 AM
Data Sourced
via MITRE·01:29 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2587?
CVE-2011-2587 has a high severity rating as it allows remote attackers to potentially execute arbitrary code.
2
How do I fix CVE-2011-2587?
To fix CVE-2011-2587, upgrade VLC media player to version 1.1.11 or later.
3
What versions of VLC are affected by CVE-2011-2587?
Vulnerable versions include VLC media player 1.1.0 to 1.1.10.
4
What is the impact of CVE-2011-2587?
The impact of CVE-2011-2587 includes application crashes and the possibility of arbitrary code execution.
5
Is there a workaround for CVE-2011-2587?
The best workaround for CVE-2011-2587 is to avoid opening untrusted Real Media files until VLC is updated.