Lucene search

K
freebsdFreeBSD62F36DFD-FF56-11E1-8821-001B2134EF46
HistoryMar 12, 2012 - 12:00 a.m.

vlc -- arbitrary code execution in Real RTSP and MMS support

2012-03-1200:00:00
vuxml.freebsd.org
9

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.965

Percentile

99.6%

Jean-Baptiste Kempf, on behalf of the VideoLAN project reports:

If successful, a malicious third party could crash the VLC
media player process. Arbitrary code execution could be possible
on some systems.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchvlc<Β 2.0.1,3UNKNOWN

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.965

Percentile

99.6%