CVE-2011-3623
EPSS 3.7%
Description
Multiple stack-based buffer overflows in VideoLAN VLC media player before 1.0.2 allow remote attackers to execute arbitrary code via (1) a crafted ASF file, related to the ASF_ObjectDumpDebug function in modules/demux/asf/libasf.c; (2) a crafted AVI file, related to the AVI_ChunkDumpDebug_level function in modules/demux/avi/libavi.c; or (3) a crafted MP4 file, related to the __MP4_BoxDumpStructure function in modules/demux/mp4/libmp4.c.
How to fix CVE-2011-3623
To remediate CVE-2011-3623, upgrade the affected package to a fixed version below.
- Debian/vlc—upgrade to 1.1.3-1 or later
Is CVE-2011-3623 being exploited?
Low — EPSS is 3.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.1.3-1