First published: Thu Feb 06 2020(Updated: )
The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view directory listings via the 'dir' command or issue other commands without authenticating.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Videolan Vlc Media Player | <2.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3564 is a vulnerability in VideoLAN VLC media player before version 2.0.7 that allows remote attackers to view directory listings or issue commands without authentication.
The severity of CVE-2013-3564 is medium with a CVSS score of 5.3.
CVE-2013-3564 affects VideoLAN VLC media player versions before 2.0.7.
To fix CVE-2013-3564, you should update VideoLAN VLC media player to version 2.0.7 or later.
Yes, you can find more information about CVE-2013-3564 at the following link: [https://www3.trustwave.com/spiderlabs/advisories/TWSL2013-007.txt](https://www3.trustwave.com/spiderlabs/advisories/TWSL2013-007.txt)