CVE-2010-2937

Publication date 20 August 2010

Last updated 24 July 2024


Ubuntu priority

The ReadMetaFromId3v2 function in taglib.cpp in the TagLib plugin in VideoLAN VLC media player 0.9.0 through 1.1.2 does not properly process ID3v2 tags, which allows remote attackers to cause a denial of service (application crash) via a crafted media file.

Status

Package Ubuntu Release Status
vlc 11.04 natty
Fixed 1.1.3-2ubuntu1
10.10 maverick
Fixed 1.1.3-2ubuntu1
10.04 LTS lucid
Fixed 1.0.6-1ubuntu1.2
9.10 karmic Ignored end of life
9.04 jaunty Ignored end of life
8.04 LTS hardy Ignored end of life
6.06 LTS dapper Ignored end of life