CVE-2012-3377

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
12/07/2012
Last modified:
11/04/2025

Description

Heap-based buffer overflow in the Ogg_DecodePacket function in the OGG demuxer (modules/demux/ogg.c) in VideoLAN VLC media player before 2.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted OGG file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:*:*:* 2.0.1 (including)
cpe:2.3:a:videolan:vlc_media_player:0.1.99a:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.1.99b:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.1.99c:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.1.99d:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.1.99e:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.1.99f:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.1.99g:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.1.99h:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.1.99i:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.2.0:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.2.50:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.2.60:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.2.61:*:*:*:*:*:*:*
cpe:2.3:a:videolan:vlc_media_player:0.2.62:*:*:*:*:*:*:*