Candidate: CVE-2011-1684 PublicDate: 2011-05-03 20:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1684 Description: Heap-based buffer overflow in the MP4_ReadBox_skcr function in libmp4.c in the MP4 demultiplexer in VideoLAN VLC media player 1.x before 1.1.9 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted MP4 file. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/ubuntu/+source/vlc/+bug/756368 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_vlc: upstream: http://git.videolan.org/?p=vlc.git;a=commit;h=5637ca8141bf39f263ecdb62035d2cb45c740821 (head) upstream: http://git.videolan.org/?p=vlc/vlc-1.1.git;a=commit;h=234d6579da56412b574cc473aa8bf97adc3ffc8e (1.1) upstream_vlc: released (1.1.9) dapper_vlc: ignored (reached end-of-life) hardy_vlc: ignored (reached end-of-life) karmic_vlc: ignored (reached end-of-life) lucid_vlc: released (1.0.6-1ubuntu1.6) maverick_vlc: released (1.1.4-1ubuntu1.5) natty_vlc: not-affected (1.1.9-1ubuntu1) devel_vlc: not-affected (1.1.9-1ubuntu1)