Oval Definition:oval:org.mitre.oval:def:24040
Revision Date:2014-04-28Version:5
Title:VLC Media Player RTSP Processing "parseRTSPRequestString()" Buffer Overflow Vulnerability
Description:The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a space character at the beginning of an RTSP message, which triggers an integer underflow, infinite loop, and buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6933.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2013-6934
Platform(s):Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Vista
Microsoft Windows XP
Product(s):VLC Media Player
Definition Synopsis
  • VLC media player is installed
  • AND Version of VLC Media Player is less than 2.1.2 and greater than or equal 2.0.0
  • BACK