UBUNTU-CVE-2012-5855

Source
https://ubuntu.com/security/CVE-2012-5855
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-5855.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2012-5855
Related
  • CVE-2012-5855
Published
2013-07-10T19:55:00Z
Modified
2013-07-10T19:55:00Z
Summary
[none]
Details

The SHAddToRecentDocs function in VideoLAN VLC media player 2.0.4 and earlier might allow user-assisted attackers to cause a denial of service (crash) via a crafted file name that triggers an incorrect string-length calculation when the file is added to VLC. NOTE: it is not clear whether this issue crosses privilege boundaries or whether it can be exploited without user interaction.

References

Affected packages

Ubuntu:Pro:14.04:LTS / vlc

Package

Name
vlc
Purl
pkg:deb/ubuntu/vlc?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.0.8-1
2.1.1-1
2.1.2-1
2.1.2-2
2.1.2-2build1
2.1.2-2build2
2.1.4-0ubuntu14.04.1
2.1.6-0ubuntu14.04.1
2.1.6-0ubuntu14.04.2
2.1.6-0ubuntu14.04.3
2.1.6-0ubuntu14.04.4
2.1.6-0ubuntu14.04.5+esm1

Ecosystem specific

{
    "ubuntu_priority": "negligible"
}