Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2011-2588


Heap-based buffer overflow in the AVI_ChunkRead_strf function in libavi.c in the AVI demuxer in VideoLAN VLC media player before 1.1.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted AVI media file.


Published

2011-07-27T02:55:02.273

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application videolan vlc_media_player ≤ 1.1.10.1 Yes
Application videolan vlc_media_player 0.1.99b Yes
Application videolan vlc_media_player 0.1.99e Yes
Application videolan vlc_media_player 0.1.99f Yes
Application videolan vlc_media_player 0.1.99g Yes
Application videolan vlc_media_player 0.1.99h Yes
Application videolan vlc_media_player 0.1.99i Yes
Application videolan vlc_media_player 0.2.0 Yes
Application videolan vlc_media_player 0.2.60 Yes
Application videolan vlc_media_player 0.2.61 Yes
Application videolan vlc_media_player 0.2.62 Yes
Application videolan vlc_media_player 0.2.63 Yes
Application videolan vlc_media_player 0.2.70 Yes
Application videolan vlc_media_player 0.2.71 Yes
Application videolan vlc_media_player 0.2.72 Yes
Application videolan vlc_media_player 0.2.73 Yes
Application videolan vlc_media_player 0.2.80 Yes
Application videolan vlc_media_player 0.2.81 Yes
Application videolan vlc_media_player 0.2.82 Yes
Application videolan vlc_media_player 0.2.83 Yes
Application videolan vlc_media_player 0.2.90 Yes
Application videolan vlc_media_player 0.2.91 Yes
Application videolan vlc_media_player 0.2.92 Yes
Application videolan vlc_media_player 0.3.0 Yes
Application videolan vlc_media_player 0.3.1 Yes
Application videolan vlc_media_player 0.4.0 Yes
Application videolan vlc_media_player 0.4.1 Yes
Application videolan vlc_media_player 0.4.2 Yes
Application videolan vlc_media_player 0.4.3 Yes
Application videolan vlc_media_player 0.4.4 Yes
Application videolan vlc_media_player 0.4.5 Yes
Application videolan vlc_media_player 0.4.6 Yes
Application videolan vlc_media_player 0.5.0 Yes
Application videolan vlc_media_player 0.5.1 Yes
Application videolan vlc_media_player 0.5.2 Yes
Application videolan vlc_media_player 0.5.3 Yes
Application videolan vlc_media_player 0.6.0 Yes
Application videolan vlc_media_player 0.6.1 Yes
Application videolan vlc_media_player 0.6.2 Yes
Application videolan vlc_media_player 0.7.0 Yes
Application videolan vlc_media_player 0.7.2 Yes
Application videolan vlc_media_player 0.8.0 Yes
Application videolan vlc_media_player 0.8.1 Yes
Application videolan vlc_media_player 0.8.2 Yes
Application videolan vlc_media_player 0.8.4 Yes
Application videolan vlc_media_player 0.8.5 Yes
Application videolan vlc_media_player 0.8.6 Yes
Application videolan vlc_media_player 0.9.2 Yes
Application videolan vlc_media_player 0.9.3 Yes
Application videolan vlc_media_player 0.9.4 Yes
Application videolan vlc_media_player 0.9.5 Yes
Application videolan vlc_media_player 0.9.6 Yes
Application videolan vlc_media_player 0.9.8a Yes
Application videolan vlc_media_player 0.9.9 Yes
Application videolan vlc_media_player 0.9.10 Yes
Application videolan vlc_media_player 1.0.0 Yes
Application videolan vlc_media_player 1.0.1 Yes
Application videolan vlc_media_player 1.0.2 Yes
Application videolan vlc_media_player 1.0.3 Yes
Application videolan vlc_media_player 1.0.4 Yes
Application videolan vlc_media_player 1.0.5 Yes
Application videolan vlc_media_player 1.0.6 Yes
Application videolan vlc_media_player 1.1.0 Yes
Application videolan vlc_media_player 1.1.1 Yes
Application videolan vlc_media_player 1.1.2 Yes
Application videolan vlc_media_player 1.1.3 Yes
Application videolan vlc_media_player 1.1.4 Yes
Application videolan vlc_media_player 1.1.5 Yes
Application videolan vlc_media_player 1.1.6 Yes
Application videolan vlc_media_player 1.1.6.1 Yes
Application videolan vlc_media_player 1.1.7 Yes
Application videolan vlc_media_player 1.1.8 Yes
Application videolan vlc_media_player 1.1.9 Yes
Application videolan vlc_media_player 1.1.10 Yes

References