CVE-2013-3564Sensitive Information Exposure in VLC Media Player

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 53.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 6
Latest updateMay 5

Description

The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view directory listings via the 'dir' command or issue other commands without authenticating.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
GHSA-8442-g6hc-g9m7: The web interface in VideoLAN VLC media player before 22022-05-05
CVEList
CVE-2013-3564: The web interface in VideoLAN VLC media player before 22020-02-06
OSV
CVE-2013-3564: The web interface in VideoLAN VLC media player before 22020-02-06

📋Vendor Advisories

1
Debian
CVE-2013-3564: vlc - The web interface in VideoLAN VLC media player before 2.0.7 has no access contro...2013
CVE-2013-3564 — Sensitive Information Exposure | cvebase