First published: Wed May 14 2014(Updated: )
codec\libpng_plugin.dll in VideoLAN VLC Media Player 2.1.3 allows remote attackers to cause a denial of service (crash) via a crafted .png file, as demonstrated by a png in a .wave file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VLC Media Player | =2.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3441 has a severity rating of medium due to its potential to cause a denial of service.
To fix CVE-2014-3441, upgrade to VLC Media Player version 2.1.4 or later, which resolves this vulnerability.
CVE-2014-3441 is associated with remote denial of service attacks through the exploitation of crafted PNG files.
VLC Media Player version 2.1.3 is the specific version affected by CVE-2014-3441.
While CVE-2014-3441 primarily causes a crash, it may indirectly affect data handling during the crash.