CVE-2011-0531
CVE-2011-0531
demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary commands via a crafted MKV (WebM or Matroska) file that triggers memory corruption, related to "class mismatching" and the MKV_IS_ID macro.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/16637unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=59491dcedffbf97612d2c572943b56ee4289dd07http://osvdb.org/70698http://secunia.com/advisories/43131http://secunia.com/advisories/43242https://exchange.xforce.ibmcloud.com/vulnerabilities/65045https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12415http://www.debian.org/security/2011/dsa-2159http://www.openwall.com/lists/oss-security/2011/01/31/4http://www.openwall.com/lists/oss-security/2011/01/31/8http://www.securityfocus.com/bid/46060http://www.securitytracker.com/id?1025018http://www.videolan.org/security/sa1102.html