Candidate: CVE-2010-0364 PublicDate: 2010-01-21 20:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0364 Description: Stack-based buffer overflow in VideoLAN VLC Media Player 0.8.6 allows user-assisted remote attackers to execute arbitrary code via an ogg file with a crafted Advanced SubStation Alpha Subtitle (.ass) file, probably involving the Dialogue field. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_vlc: upstream_vlc: released (1.0.5) dapper_vlc: ignored (reached end-of-life) hardy_vlc: ignored (reached end-of-life) intrepid_vlc: needs-triage (reached end-of-life) jaunty_vlc: ignored (reached end-of-life) karmic_vlc: ignored (reached end-of-life) lucid_vlc: not-affected (1.0.5-2ubuntu1) maverick_vlc: not-affected (1.0.5-2ubuntu1) natty_vlc: not-affected (1.0.5-2ubuntu1) devel_vlc: not-affected (1.0.5-2ubuntu1)