CVE-2011-0021
published 2011-01-25CVE-2011-0021: Multiple heap-based buffer overflows in cdg.c in the CDG decoder in VideoLAN VLC Media Player before 1.1.6 allow remote attackers to cause a denial of service…
PriorityP340critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.78%
92.2th percentile
Multiple heap-based buffer overflows in cdg.c in the CDG decoder in VideoLAN VLC Media Player before 1.1.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted CDG video.
Affected
72 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | vlc | < vlc 1.1.3-1squeeze2 (bookworm) | vlc 1.1.3-1squeeze2 (bookworm) |
| videolan | vlc_media_player | <= 1.1.5 | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
| videolan | vlc_media_player | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-62w2-x3mc-cwxp: Multiple heap-based buffer overflows in cdg
ghsa_unreviewed·2022-05-03
CVE-2011-0021 [HIGH] CWE-119 GHSA-62w2-x3mc-cwxp: Multiple heap-based buffer overflows in cdg
Multiple heap-based buffer overflows in cdg.c in the CDG decoder in VideoLAN VLC Media Player before 1.1.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted CDG video.
OSV
CVE-2011-0021: Multiple heap-based buffer overflows in cdg
osv·2011-01-25·CVSS 9.3
CVE-2011-0021 [CRITICAL] CVE-2011-0021: Multiple heap-based buffer overflows in cdg
Multiple heap-based buffer overflows in cdg.c in the CDG decoder in VideoLAN VLC Media Player before 1.1.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted CDG video.
Debian
CVE-2011-0021: vlc - Multiple heap-based buffer overflows in cdg.c in the CDG decoder in VideoLAN VLC...
vendor_debian·2011·CVSS 9.3
CVE-2011-0021 [CRITICAL] CVE-2011-0021: vlc - Multiple heap-based buffer overflows in cdg.c in the CDG decoder in VideoLAN VLC...
Multiple heap-based buffer overflows in cdg.c in the CDG decoder in VideoLAN VLC Media Player before 1.1.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted CDG video.
Scope: local
bookworm: resolved (fixed in 1.1.3-1squeeze2)
bullseye: resolved (fixed in 1.1.3-1squeeze2)
forky: resolved (fixed in 1.1.3-1squeeze2)
sid: resolved (fixed in 1.1.3-1squeeze2)
trixie: resolved (fixed in 1.1.3-1squeeze2)
No detection rules found.
No public exploits indexed.
http://download.videolan.org/pub/videolan/vlc/1.1.6/vlc-1.1.6.tar.bz2http://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=f9b664eac0e1a7bceed9d7b5854fd9fc351b4aabhttp://openwall.com/lists/oss-security/2011/01/19/6http://openwall.com/lists/oss-security/2011/01/20/3http://www.securityfocus.com/bid/45927http://www.vupen.com/english/advisories/2011/0185https://exchange.xforce.ibmcloud.com/vulnerabilities/64879https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12460http://download.videolan.org/pub/videolan/vlc/1.1.6/vlc-1.1.6.tar.bz2http://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=f9b664eac0e1a7bceed9d7b5854fd9fc351b4aabhttp://openwall.com/lists/oss-security/2011/01/19/6http://openwall.com/lists/oss-security/2011/01/20/3http://www.securityfocus.com/bid/45927http://www.vupen.com/english/advisories/2011/0185https://exchange.xforce.ibmcloud.com/vulnerabilities/64879https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12460
2011-01-25
Published