CVE-2011-3623: Buffer Overflow
Multiple stack-based buffer overflows in VideoLAN VLC media player before 1.0.2 allow remote attackers to execute arbitrary code via (1) a crafted ASF file, related to the ASFObjectDumpDebug function in modules/demux/asf/libasf.c; (2) a crafted AVI file, related to the AVIChunkDumpDebuglevel function in modules/demux/avi/libavi.c; or (3) a crafted MP4 file, related to the MP4BoxDumpStructure function in modules/demux/mp4/libmp4.c.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3623?
CVE-2011-3623 has a critical severity rating due to the potential for remote code execution.
How do I fix CVE-2011-3623?
To fix CVE-2011-3623, users should update VLC media player to version 1.0.2 or later.
What versions of VLC are affected by CVE-2011-3623?
CVE-2011-3623 affects all VLC media player versions prior to 1.0.2.
Can CVE-2011-3623 be exploited remotely?
Yes, CVE-2011-3623 can be exploited remotely through crafted ASF and AVI files.
What should I do if I'm running an affected version of VLC due to CVE-2011-3623?
If running an affected version of VLC media player, immediately upgrade to a patched version to mitigate the vulnerability.