CVE Vulnerabilities

CVE-2012-5855

Published: Jul 10, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

The SHAddToRecentDocs function in VideoLAN VLC media player 2.0.4 and earlier might allow user-assisted attackers to cause a denial of service (crash) via a crafted file name that triggers an incorrect string-length calculation when the file is added to VLC. NOTE: it is not clear whether this issue crosses privilege boundaries or whether it can be exploited without user interaction.

Affected Software

NameVendorStart VersionEnd Version
Vlc_media_playerVideolan*2.0.4 (including)
Vlc_media_playerVideolan2.0.0 (including)2.0.0 (including)
Vlc_media_playerVideolan2.0.1 (including)2.0.1 (including)
Vlc_media_playerVideolan2.0.2 (including)2.0.2 (including)
Vlc_media_playerVideolan2.0.3 (including)2.0.3 (including)
VlcUbuntudevel*
VlcUbuntuhardy*
VlcUbuntulucid*
VlcUbuntuoneiric*
VlcUbuntuprecise*
VlcUbuntuquantal*
VlcUbunturaring*
VlcUbuntusaucy*
VlcUbuntutrusty*
VlcUbuntutrusty/esm*
VlcUbuntuutopic*

References