CVE-2010-0364
EPSS 20.6%
Description
Stack-based buffer overflow in VideoLAN VLC Media Player 0.8.6 allows user-assisted remote attackers to execute arbitrary code via an ogg file with a crafted Advanced SubStation Alpha Subtitle (.ass) file, probably involving the Dialogue field.
How to fix CVE-2010-0364
To remediate CVE-2010-0364, upgrade the affected package to a fixed version below.
- Debian/vlc—upgrade to 0.8.6.c-4.1 or later
Is CVE-2010-0364 being exploited?
Moderate — EPSS is 20.6%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 0.8.6.c-4.1