CVE-2014-1684: Medium severity Videolan VLC Media Player vulnerability
Published Mar 3, 2014
·Updated
The ASFReadObjectfileproperties function in modules/demux/asf/libasf.c in the ASF Demuxer in VideoLAN VLC Media Player before 2.1.3 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a zero minimum and maximum data packet size in an ASF file.
Affected Software
37 affected components
Videolan VLC Media Player<=2.1.2
Videolan VLC Media Player=1.0.0
Videolan VLC Media Player=1.0.1
Videolan VLC Media Player=1.0.2
Videolan VLC Media Player=1.0.3
Videolan VLC Media Player=1.0.4
Videolan VLC Media Player=1.0.5
Videolan VLC Media Player=1.0.6
Videolan VLC Media Player=1.1.0
Videolan VLC Media Player=1.1.1
Videolan VLC Media Player=1.1.2
Videolan VLC Media Player=1.1.3
Videolan VLC Media Player=1.1.4
Videolan VLC Media Player=1.1.4.1
Videolan VLC Media Player=1.1.5
Videolan VLC Media Player=1.1.6
Videolan VLC Media Player=1.1.6.1
Videolan VLC Media Player=1.1.7
Videolan VLC Media Player=1.1.8
Videolan VLC Media Player=1.1.9
Videolan VLC Media Player=1.1.10
Videolan VLC Media Player=1.1.10.1
Videolan VLC Media Player=1.1.11
Videolan VLC Media Player=1.1.12
Videolan VLC Media Player=1.1.13
Videolan VLC Media Player=2.0.0
Videolan VLC Media Player=2.0.1
Videolan VLC Media Player=2.0.2
Videolan VLC Media Player=2.0.3
Videolan VLC Media Player=2.0.4
Videolan VLC Media Player=2.0.5
Videolan VLC Media Player=2.0.6
Videolan VLC Media Player=2.0.7
Videolan VLC Media Player=2.0.8
Videolan VLC Media Player=2.0.9
Videolan VLC Media Player=2.1.0
Videolan VLC Media Player=2.1.1
Remediation
Event History
Mar 3, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1684?
CVE-2014-1684 has a medium severity rating, primarily due to its potential to cause a denial of service.
2
How do I fix CVE-2014-1684?
To fix CVE-2014-1684, update VLC Media Player to version 2.1.3 or later.
3
What is the impact of CVE-2014-1684?
The impact of CVE-2014-1684 is a denial of service, leading to a crash of VLC Media Player.
4
Which versions of VLC Media Player are affected by CVE-2014-1684?
Versions of VLC Media Player prior to 2.1.3 are affected by CVE-2014-1684.
5
Can CVE-2014-1684 be exploited remotely?
Yes, CVE-2014-1684 can be exploited remotely through specially crafted ASF files.