CVE-2011-0021Improper Restriction of Operations within the Bounds of a Memory Buffer in VLC Media Player

Severity
9.3CRITICALNVD
EPSS
10.3%
top 6.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 25
Latest updateMay 3

Description

Multiple heap-based buffer overflows in cdg.c in the CDG decoder in VideoLAN VLC Media Player before 1.1.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted CDG video.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

Debianvideolan/vlc_media_player< 1.1.3-1squeeze2+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-62w2-x3mc-cwxp: Multiple heap-based buffer overflows in cdg2022-05-03
CVEList
CVE-2011-0021: Multiple heap-based buffer overflows in cdg2011-01-25
OSV
CVE-2011-0021: Multiple heap-based buffer overflows in cdg2011-01-25

📋Vendor Advisories

1
Debian
CVE-2011-0021: vlc - Multiple heap-based buffer overflows in cdg.c in the CDG decoder in VideoLAN VLC...2011

💬Community

1
Bugzilla
CVE-2011-4295 CVE-2011-4296 moodle: multiple flaws in 2.x < 2.0.4 (MSA-11-0021, MSA-11-0022)2011-08-11
CVE-2011-0021 — Videolan VLC Media Player vulnerability | cvebase