CVE-2010-3275
vlc - missing input sanitising
EPSS 75.5%
描述
libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an AMV file, related to a "dangling pointer vulnerability."
如何修補 CVE-2010-3275
要修補 CVE-2010-3275,請將受影響套件升級到下列已修補版本。
- Debian/vlc—升級至 1.1.8-1 或更新版本
- Debian/vlc—升級至 1.1.3-1squeeze4 或更新版本
CVE-2010-3275 正在被利用嗎?
可能 — EPSS 為 75.5%,屬於高被利用機率區間,建議優先修補。
受影響套件(2)
- from 0, < 1.1.8-1
- from 0, < 1.1.3-1squeeze4