CVE-2013-3245 Information
Description
LICENSE README.md cvefilelist cvelist nvdcve nvdpages.sh scripts test-CVE-2017-1882.markdown test-CVE-2017-18822.markdown tmpvendorlinks DISPUTED LICENSE README.md cvefilelist cvelist nvdcve nvdpages.sh scripts test-CVE-2017-1882.markdown test-CVE-2017-18822.markdown tmpvendorlinks plugins/demux/libmkv_plugin.dll in VideoLAN VLC Media Player 2.0.7 and possibly other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MKV file possibly involving an integer overflow and out-of-bounds read or heap-based buffer overflow or an uncaught exception. NOTE: the vendor disputes the severity and claimed vulnerability type of this issue stating \This PoC crashes VLC indeed but does nothing more… this is not an integer overflow error but an uncaught exception and I doubt that it is exploitable. This uncaught exception makes VLC abort not execute random code on my Linux 64bits machine.\ A PoC posted by the original researcher shows signs of an attacker-controlled out-of-bounds read but the affected instruction does not involve a register that directly influences control flow.
Reference
http://seclists.org/fulldisclosure/2013/Jul/71 http://seclists.org/fulldisclosure/2013/Jul/77 http://seclists.org/fulldisclosure/2013/Jul/79 http://secunia.com/advisories/52956 http://secunia.com/blog/372/ http://www.jbkempf.com/blog/post/2013/More-lies-from-Secunia http://www.securityfocus.com/bid/61032
Share on: