CVE-2013-1868: Buffer Overflow
Published Jul 10, 2013
·Updated
Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to the (1) freetype renderer and (2) HTML subtitle parser.
Affected Software
5 affected components
Videolan VLC Media Player<=2.0.4
Videolan VLC Media Player=2.0.0
Videolan VLC Media Player=2.0.1
Videolan VLC Media Player=2.0.2
Videolan VLC Media Player=2.0.3
Event History
Jul 10, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1868?
CVE-2013-1868 is classified as a high severity vulnerability due to the potential for remote code execution and denial of service.
2
How do I fix CVE-2013-1868?
To fix CVE-2013-1868, update the VLC media player to version 2.0.5 or later.
3
What versions are affected by CVE-2013-1868?
CVE-2013-1868 affects VLC media player versions 2.0.4 and earlier.
4
What are the potential impacts of CVE-2013-1868?
The impacts of CVE-2013-1868 include crashing the application and allowing remote attackers to execute arbitrary code.
5
Which components of VLC are vulnerable in CVE-2013-1868?
The vulnerable components in CVE-2013-1868 are the freetype renderer and the HTML subtitle parser.