First published: Fri Oct 25 2013(Updated: )
VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a URL in a m3u file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VideoLAN VLC media player | <=2.0.8 | |
VideoLAN VLC media player | =1.0.0 | |
VideoLAN VLC media player | =1.0.1 | |
VideoLAN VLC media player | =1.0.2 | |
VideoLAN VLC media player | =1.0.3 | |
VideoLAN VLC media player | =1.0.4 | |
VideoLAN VLC media player | =1.0.5 | |
VideoLAN VLC media player | =1.0.6 | |
VideoLAN VLC media player | =1.1.0 | |
VideoLAN VLC media player | =1.1.1 | |
VideoLAN VLC media player | =1.1.2 | |
VideoLAN VLC media player | =1.1.3 | |
VideoLAN VLC media player | =1.1.4 | |
VideoLAN VLC media player | =1.1.4.1 | |
VideoLAN VLC media player | =1.1.5 | |
VideoLAN VLC media player | =1.1.6 | |
VideoLAN VLC media player | =1.1.6.1 | |
VideoLAN VLC media player | =1.1.7 | |
VideoLAN VLC media player | =1.1.8 | |
VideoLAN VLC media player | =1.1.9 | |
VideoLAN VLC media player | =1.1.10 | |
VideoLAN VLC media player | =1.1.10.1 | |
VideoLAN VLC media player | =1.1.11 | |
VideoLAN VLC media player | =1.1.12 | |
VideoLAN VLC media player | =1.1.13 | |
VideoLAN VLC media player | =2.0.0 | |
VideoLAN VLC media player | =2.0.1 | |
VideoLAN VLC media player | =2.0.2 | |
VideoLAN VLC media player | =2.0.3 | |
VideoLAN VLC media player | =2.0.4 | |
VideoLAN VLC media player | =2.0.5 | |
VideoLAN VLC media player | =2.0.6 | |
VideoLAN VLC media player | =2.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6283 is classified as a high severity vulnerability due to its potential to cause a denial of service and possibly allow arbitrary code execution.
To fix CVE-2013-6283, update VLC Media Player to version 2.0.9 or later.
CVE-2013-6283 affects VLC Media Player versions 2.0.8 and earlier, as well as several earlier major releases.
CVE-2013-6283 enables remote attackers to crash VLC Media Player and potentially execute arbitrary code through crafted m3u files.
The vendor for the CVE-2013-6283 vulnerability is VideoLAN, the organization responsible for VLC Media Player.