CVE-2013-1954
Gentoo Linux Security Advisory 201411-01
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The ASF Demuxer (modules/demux/asf/asf.c) in VideoLAN VLC media player 2.0.5 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted ASF movie that triggers an out-of-bounds read.
El ASF Demuxer (modules/demux/asf/asf.c) en VideoLAN VLC media player v2.0.5 y anteriores permite a atacantes remotos provocar una denegación de servicio (caída) y posiblemente ejecutar código arbitrario a través de un fichero ASF especialmente diseñado que genera una lectura fuera de los límites.
Multiple buffer overflows have been found in the VideoLAN media player. Processing malformed subtitles or movie files could lead to denial of service and potentially the execution of arbitrary code.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-02-19 CVE Reserved
- 2013-07-10 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://git.videolan.org/?p=vlc.git%3Ba=commitdiff%3Bh=b31ce523331aa3a6e620b68cdfe3f161d519631e | X_refsource_confirm | |
http://marc.info/?l=oss-security&m=136593191416152&w=2 | Mailing List | |
http://marc.info/?l=oss-security&m=136610343501731&w=2 | Mailing List | |
http://secunia.com/advisories/59793 | Third Party Advisory | |
http://www.osvdb.org/89598 | Vdb Entry | |
http://www.securityfocus.com/bid/57333 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17023 | Signature |
URL | Date | SRC |
---|---|---|
http://trac.videolan.org/vlc/ticket/8024 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.videolan.org/security/sa1302.html | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Videolan Search vendor "Videolan" | Vlc Media Player Search vendor "Videolan" for product "Vlc Media Player" | <= 2.0.5 Search vendor "Videolan" for product "Vlc Media Player" and version " <= 2.0.5" | - |
Affected
| ||||||
Videolan Search vendor "Videolan" | Vlc Media Player Search vendor "Videolan" for product "Vlc Media Player" | 2.0.0 Search vendor "Videolan" for product "Vlc Media Player" and version "2.0.0" | - |
Affected
| ||||||
Videolan Search vendor "Videolan" | Vlc Media Player Search vendor "Videolan" for product "Vlc Media Player" | 2.0.1 Search vendor "Videolan" for product "Vlc Media Player" and version "2.0.1" | - |
Affected
| ||||||
Videolan Search vendor "Videolan" | Vlc Media Player Search vendor "Videolan" for product "Vlc Media Player" | 2.0.2 Search vendor "Videolan" for product "Vlc Media Player" and version "2.0.2" | - |
Affected
| ||||||
Videolan Search vendor "Videolan" | Vlc Media Player Search vendor "Videolan" for product "Vlc Media Player" | 2.0.3 Search vendor "Videolan" for product "Vlc Media Player" and version "2.0.3" | - |
Affected
| ||||||
Videolan Search vendor "Videolan" | Vlc Media Player Search vendor "Videolan" for product "Vlc Media Player" | 2.0.4 Search vendor "Videolan" for product "Vlc Media Player" and version "2.0.4" | - |
Affected
|