VulnerabilityModified
CVE-2010-2937
The ReadMetaFromId3v2 function in taglib.cpp in the TagLib plugin in VideoLAN VLC media player 0.9.0 through 1.1.2 does not properly process ID3v2 tags, which allows remote attackers to cause a denial of service (application crash) via a crafted media…
MEDIUM 5.0EPSS 2.64%
Does this matter?
Lower severity and a low EPSS score (2.64%). Track it; it rarely justifies an emergency change on its own.
Description
The ReadMetaFromId3v2 function in taglib.cpp in the TagLib plugin in VideoLAN VLC media player 0.9.0 through 1.1.2 does not properly process ID3v2 tags, which allows remote attackers to cause a denial of service (application crash) via a crafted media file.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 2.64% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- videolan/vlc media player
- Source
- secalert@redhat.com
References
- http://git.videolan.org/?p=vlc/vlc-1.0.git%3Ba=commit%3Bh=22a22e356c9d93993086810b2e25b59b55925b3a
- http://git.videolan.org/?p=vlc/vlc-1.1.git%3Ba=commit%3Bh=24918843e57c7962e28fcb01845adce82bed6516
- http://www.securityfocus.com/bid/42386
- http://www.videolan.org/security/sa1004.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2010/2087
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14676
- http://git.videolan.org/?p=vlc/vlc-1.0.git%3Ba=commit%3Bh=22a22e356c9d93993086810b2e25b59b55925b3a
- http://git.videolan.org/?p=vlc/vlc-1.1.git%3Ba=commit%3Bh=24918843e57c7962e28fcb01845adce82bed6516
- http://www.securityfocus.com/bid/42386
- http://www.videolan.org/security/sa1004.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2010/2087
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14676
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.