Vulnerability Name: | CVE-2013-4388 (CCN-87615) | ||||||||||||||||||||||||||||
Assigned: | 2013-09-29 | ||||||||||||||||||||||||||||
Published: | 2013-09-29 | ||||||||||||||||||||||||||||
Updated: | 2017-09-19 | ||||||||||||||||||||||||||||
Summary: | Buffer overflow in the mp4a packetizer (modules/packetizer/mpeg4audio.c) in VideoLAN VLC Media Player before 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-4388 Source: CCN Type: VideoLAN GIT Repository VideoLAN: Free Multimedia Solutions Source: CONFIRM Type: Exploit, Patch http://git.videolan.org/?p=vlc.git;a=commitdiff;h=9794ec1cd268c04c8bca13a5fae15df6594dff3e Source: CCN Type: oss-sec mailing list, Mon, 30 Sep 2013 18:33:33 -0600 Re: CVE request: VLC Source: SECUNIA Type: UNKNOWN 59793 Source: MLIST Type: UNKNOWN [oss-security] 20130930 Re: CVE request: VLC Source: BID Type: UNKNOWN 62724 Source: CCN Type: BID-62724 VLC Media Player CVE-2013-4388 Buffer Overflow Vulnerability Source: CCN Type: SecurityTracker Alert ID: 1029120 VLC Media Player Buffer Overflow in MP4A Packetizer Lets Remote Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1029120 Source: CCN Type: VLC Media Player Web Site VLC Media Player Source: CONFIRM Type: UNKNOWN http://www.videolan.org/developers/vlc-branch/NEWS Source: XF Type: UNKNOWN vlcmediaplayer-cve20134388-mp4a-bo(87615) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:18086 Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-4388 | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |