CVE-2013-3564: Infoleak
The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view directory listings via the 'dir' command or issue other commands without authenticating.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2013-3564?
CVE-2013-3564 is a vulnerability in VideoLAN VLC media player before version 2.0.7 that allows remote attackers to view directory listings or issue commands without authentication.
What is the severity of CVE-2013-3564?
The severity of CVE-2013-3564 is medium with a CVSS score of 5.3.
How does CVE-2013-3564 affect VideoLAN VLC media player?
CVE-2013-3564 affects VideoLAN VLC media player versions before 2.0.7.
How can I fix CVE-2013-3564?
To fix CVE-2013-3564, you should update VideoLAN VLC media player to version 2.0.7 or later.
Is there any more information available about CVE-2013-3564?
Yes, you can find more information about CVE-2013-3564 at the following link: [https://www3.trustwave.com/spiderlabs/advisories/TWSL2013-007.txt](https://www3.trustwave.com/spiderlabs/advisories/TWSL2013-007.txt)