CVE-2011-2587

Heap-based buffer overflow in the DemuxAudioSipr function in real.c in the RealMedia demuxer in VideoLAN VLC media player 1.1.x before 1.1.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Real Media file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:videolan:vlc_media_player:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:1.1.3:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:1.1.4:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:1.1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:1.1.5:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:1.1.6:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:1.1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:1.1.7:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:1.1.8:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:1.1.9:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:1.1.10:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:1.1.10.1:*:*:*:*:*:*:*

History

21 Nov 2024, 01:28

Type Values Removed Values Added
References () http://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=1bce40644cddee93b4b1877a94a6ce345f32852c - () http://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=1bce40644cddee93b4b1877a94a6ce345f32852c -
References () http://secunia.com/advisories/45066 - Vendor Advisory () http://secunia.com/advisories/45066 - Vendor Advisory
References () http://www.securityfocus.com/bid/48664 - () http://www.securityfocus.com/bid/48664 -
References () http://www.videolan.org/security/sa1105.html - Patch, Vendor Advisory () http://www.videolan.org/security/sa1105.html - Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/68531 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/68531 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14851 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14851 -

07 Nov 2023, 02:07

Type Values Removed Values Added
References
  • {'url': 'http://git.videolan.org/?p=vlc.git;a=commit;h=1bce40644cddee93b4b1877a94a6ce345f32852c', 'name': 'http://git.videolan.org/?p=vlc.git;a=commit;h=1bce40644cddee93b4b1877a94a6ce345f32852c', 'tags': ['Patch'], 'refsource': 'CONFIRM'}
  • () http://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=1bce40644cddee93b4b1877a94a6ce345f32852c -

Information

Published : 2011-07-27 02:55

Updated : 2024-11-21 01:28


NVD link : CVE-2011-2587

Mitre link : CVE-2011-2587

CVE.ORG link : CVE-2011-2587


JSON object : View

Products Affected

videolan

  • vlc_media_player
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer