First published: Wed Jul 10 2013(Updated: )
Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to the (1) freetype renderer and (2) HTML subtitle parser.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
VideoLAN VLC media player | <=2.0.4 | |
VideoLAN VLC media player | =2.0.0 | |
VideoLAN VLC media player | =2.0.1 | |
VideoLAN VLC media player | =2.0.2 | |
VideoLAN VLC media player | =2.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1868 is classified as a high severity vulnerability due to the potential for remote code execution and denial of service.
To fix CVE-2013-1868, update the VLC media player to version 2.0.5 or later.
CVE-2013-1868 affects VLC media player versions 2.0.4 and earlier.
The impacts of CVE-2013-1868 include crashing the application and allowing remote attackers to execute arbitrary code.
The vulnerable components in CVE-2013-1868 are the freetype renderer and the HTML subtitle parser.