First published: Wed Jul 10 2013(Updated: )
The ASF Demuxer (modules/demux/asf/asf.c) in VideoLAN VLC media player 2.0.5 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted ASF movie that triggers an out-of-bounds read.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
VideoLAN VLC media player | <=2.0.5 | |
VideoLAN VLC media player | =2.0.0 | |
VideoLAN VLC media player | =2.0.1 | |
VideoLAN VLC media player | =2.0.2 | |
VideoLAN VLC media player | =2.0.3 | |
VideoLAN VLC media player | =2.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1954 is classified with a high severity due to the potential for denial of service and arbitrary code execution.
To fix CVE-2013-1954, upgrade your VLC media player to version 2.0.6 or later.
CVE-2013-1954 affects VLC media player versions 2.0.5 and earlier.
CVE-2013-1954 enables attackers to cause a denial of service and potentially execute arbitrary code.
Yes, CVE-2013-1954 can be exploited by delivering a crafted ASF movie file to the vulnerable VLC media player.