Vulnerability Name: | CVE-2012-5855 (CCN-79823) | ||||||||||||||||
Assigned: | 2012-11-05 | ||||||||||||||||
Published: | 2012-11-05 | ||||||||||||||||
Updated: | 2017-09-19 | ||||||||||||||||
Summary: | The SHAddToRecentDocs function in VideoLAN VLC media player 2.0.4 and earlier might allow user-assisted attackers to cause a denial of service (crash) via a crafted file name that triggers an incorrect string-length calculation when the file is added to VLC. Note: it is not clear whether this issue crosses privilege boundaries or whether it can be exploited without user interaction. | ||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P) 3.5 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:UR)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:UR)
| ||||||||||||||||
Vulnerability Type: | CWE-189 | ||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2012-5855 Source: MLIST Type: UNKNOWN [oss-security] 20121112 VLC 2.0.4 SHAddToRecentDocs CVE-2012-5855 Source: CCN Type: BugTraq Mailing List, Mon, 5 Nov 2012 08:54:10 GMT VideoLAN VLC Media Player <= 2.0.4 Crash Bug Source: BUGTRAQ Type: Exploit 20121105 VideoLAN VLC Media Player <= 2.0.4 Crash Bug Source: CCN Type: BID-56405 VLC Media Player 'SHAddToRecentDocs()' Function Denial of Service Vulnerability Source: CCN Type: VideoLAN Web site VideoLAN: Free Multimedia Solutions Source: XF Type: UNKNOWN vlc-shaddtorecentdocs-dos(79823) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:16781 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |