CVE Vulnerabilities

CVE-2010-1443

Published: Dec 26, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The parse_track_node function in modules/demux/playlist/xspf.c in the XSPF playlist parser in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty location element in an XML Shareable Playlist Format (XSPF) document.

Affected Software

NameVendorStart VersionEnd Version
Vlc_media_playerVideolan*1.0.5 (including)
Vlc_media_playerVideolan0.5.0 (including)0.5.0 (including)
Vlc_media_playerVideolan0.5.1 (including)0.5.1 (including)
Vlc_media_playerVideolan0.5.2 (including)0.5.2 (including)
Vlc_media_playerVideolan0.5.3 (including)0.5.3 (including)
Vlc_media_playerVideolan0.6.0 (including)0.6.0 (including)
Vlc_media_playerVideolan0.6.1 (including)0.6.1 (including)
Vlc_media_playerVideolan0.6.2 (including)0.6.2 (including)
Vlc_media_playerVideolan0.7.0 (including)0.7.0 (including)
Vlc_media_playerVideolan0.7.1 (including)0.7.1 (including)
Vlc_media_playerVideolan0.7.2 (including)0.7.2 (including)
Vlc_media_playerVideolan0.8.0 (including)0.8.0 (including)
Vlc_media_playerVideolan0.8.1 (including)0.8.1 (including)
Vlc_media_playerVideolan0.8.2 (including)0.8.2 (including)
Vlc_media_playerVideolan0.8.4 (including)0.8.4 (including)
Vlc_media_playerVideolan0.8.4a (including)0.8.4a (including)
Vlc_media_playerVideolan0.8.5 (including)0.8.5 (including)
Vlc_media_playerVideolan0.8.6 (including)0.8.6 (including)
Vlc_media_playerVideolan0.8.6a (including)0.8.6a (including)
Vlc_media_playerVideolan0.8.6b (including)0.8.6b (including)
Vlc_media_playerVideolan0.8.6c (including)0.8.6c (including)
Vlc_media_playerVideolan0.8.6d (including)0.8.6d (including)
Vlc_media_playerVideolan0.8.6e (including)0.8.6e (including)
Vlc_media_playerVideolan0.8.6f (including)0.8.6f (including)
Vlc_media_playerVideolan0.8.6g (including)0.8.6g (including)
Vlc_media_playerVideolan0.8.6h (including)0.8.6h (including)
Vlc_media_playerVideolan0.8.6i (including)0.8.6i (including)
Vlc_media_playerVideolan0.8.1337 (including)0.8.1337 (including)
Vlc_media_playerVideolan0.9.0 (including)0.9.0 (including)
Vlc_media_playerVideolan0.9.1 (including)0.9.1 (including)
Vlc_media_playerVideolan0.9.2 (including)0.9.2 (including)
Vlc_media_playerVideolan0.9.3 (including)0.9.3 (including)
Vlc_media_playerVideolan0.9.4 (including)0.9.4 (including)
Vlc_media_playerVideolan0.9.5 (including)0.9.5 (including)
Vlc_media_playerVideolan0.9.6 (including)0.9.6 (including)
Vlc_media_playerVideolan0.9.8a (including)0.9.8a (including)
Vlc_media_playerVideolan0.9.9 (including)0.9.9 (including)
Vlc_media_playerVideolan0.9.9a (including)0.9.9a (including)
Vlc_media_playerVideolan0.9.10 (including)0.9.10 (including)
Vlc_media_playerVideolan1.0.0 (including)1.0.0 (including)
Vlc_media_playerVideolan1.0.1 (including)1.0.1 (including)
Vlc_media_playerVideolan1.0.2 (including)1.0.2 (including)
Vlc_media_playerVideolan1.0.3 (including)1.0.3 (including)
Vlc_media_playerVideolan1.0.4 (including)1.0.4 (including)
VlcUbuntuhardy*
VlcUbuntuupstream*

References