CVE-2014-3441: Buffer Overflow
Published May 14, 2014
·Updated
codec\libpngplugin.dll in VideoLAN VLC Media Player 2.1.3 allows remote attackers to cause a denial of service (crash) via a crafted .png file, as demonstrated by a png in a .wave file.
Affected Software
1 affected component
Videolan VLC Media Player=2.1.3
Event History
May 14, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3441?
CVE-2014-3441 has a severity rating of medium due to its potential to cause a denial of service.
2
How do I fix CVE-2014-3441?
To fix CVE-2014-3441, upgrade to VLC Media Player version 2.1.4 or later, which resolves this vulnerability.
3
What kind of attack is CVE-2014-3441 associated with?
CVE-2014-3441 is associated with remote denial of service attacks through the exploitation of crafted PNG files.
4
Which software versions are affected by CVE-2014-3441?
VLC Media Player version 2.1.3 is the specific version affected by CVE-2014-3441.
5
Can CVE-2014-3441 cause data loss?
While CVE-2014-3441 primarily causes a crash, it may indirectly affect data handling during the crash.