CVE-2010-1443 — VLC Media Player vulnerability

5 documents5 sources
Severity
5.0MEDIUMNVD
EPSS
0.5%
top 32.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 26
Latest updateMay 2

Description

The parse_track_node function in modules/demux/playlist/xspf.c in the XSPF playlist parser in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty location element in an XML Shareable Playlist Format (XSPF) document.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

â–¶Debianvideolan/vlc_media_player< 1.0.6-1+3
â–¶NVDvideolan/vlc_media_player1.0.5+43

🔴Vulnerability Details

3
GHSA
GHSA-3g28-22mv-7m5h: The parse_track_node function in modules/demux/playlist/xspf↗2022-05-02
â–¶
CVEList
CVE-2010-1443: The parse_track_node function in modules/demux/playlist/xspf↗2014-12-26
â–¶
OSV
CVE-2010-1443: The parse_track_node function in modules/demux/playlist/xspf↗2014-12-26
â–¶

📋Vendor Advisories

1
Debian
CVE-2010-1443: vlc - The parse_track_node function in modules/demux/playlist/xspf.c in the XSPF playl...↗2010
â–¶
CVE-2010-1443 — Videolan VLC Media Player vulnerability | cvebase