vendor:
VLC Media Player
by:
Veysel HATAS
7.5
CVSS
HIGH
DEP Access Violation
DEP Access Violation
CWE
Product Name: VLC Media Player
Affected Version From: 2.1.2005
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2014-9597
CPE: a:videolan:vlc_media_player:2.1.5
Platforms Tested: Windows XP SP3
2014
VLC Player 2.1.5 DEP Access Violation Vulnerability
VLC Media Player contains a flaw that is triggered as user-supplied input is not properly sanitized when handling a specially crafted FLV file. This may allow a context-dependent attacker to corrupt memory and potentially execute arbitrary code.
Mitigation:
Unknown