Candidate: CVE-2012-5470 PublicDate: 2012-10-26 10:39:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5470 http://www.exploit-db.com/exploits/21889/ http://openwall.com/lists/oss-security/2012/10/24/3 http://www.videolan.org/security/sa1203.html Description: libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted PNG file. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/ubuntu/+source/vlc/+bug/1084054 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_vlc: upstream_vlc: released (2.0.5) hardy_vlc: ignored (reached end-of-life) lucid_vlc: ignored (reached end-of-life) natty_vlc: ignored (reached end-of-life) oneiric_vlc: ignored (reached end-of-life) precise_vlc: released (2.0.5-0ubuntu0.12.04.1) quantal_vlc: not-affected (2.0.4-0ubuntu1) raring_vlc: not-affected (2.0.4-1) saucy_vlc: not-affected (2.0.4-1) devel_vlc: not-affected (2.0.4-1)