CVE-2010-3907

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
03/01/2011
Last modified:
11/04/2025

Description

Multiple integer overflows in real.c in the Real demuxer plugin in VideoLAN VLC Media Player before 1.1.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a zero i_subpackets value in a Real Media file, leading to a heap-based buffer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:*:*:* 1.1.5 (including)
cpe:2.3:a:videolan:vlc_media_player:0.1.99b:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.1.99e:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.1.99f:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.1.99g:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.1.99h:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.1.99i:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.2.0:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.2.60:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.2.61:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.2.62:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.2.63:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.2.70:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.2.71:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.2.72:*:*:*:*:*:*:*