Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2012-2396VLC Media Player vulnerability

8 documents8 sources
Severity
4.3MEDIUMNVD
EPSS
2.5%
top 14.73%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 19
Latest updateMay 17

Description

VideoLAN VLC media player 2.0.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted MP4 file.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Debiantaglib/taglib< 1.7.2-1+3

🔴Vulnerability Details

3
GHSA
GHSA-w4px-4wpx-8xhm: VideoLAN VLC media player 22022-05-17
CVEList
CVE-2012-2396: VideoLAN VLC media player 22012-04-19
OSV
CVE-2012-2396: VideoLAN VLC media player 22012-04-19

💥Exploits & PoCs

1
Exploit-DB
VideoLAN VLC Media Player 2.0.1 - '.mp4' Crash (PoC)2012-04-19

📋Vendor Advisories

2
Red Hat
taglib: Division by zero while parsing properties of certain MP4 audio files2012-04-20
Debian
CVE-2012-2396: taglib - VideoLAN VLC media player 2.0.1 allows remote attackers to cause a denial of ser...2012

💬Community

1
Bugzilla
CVE-2012-2396 taglib: Division by zero while parsing properties of certain MP4 audio files2012-05-03
CVE-2012-2396 — Videolan VLC Media Player vulnerability | cvebase