VLC < 3.0.5 Denial of Service and/or Infoleak Vulnerability

critical Nessus Plugin ID 136895

Synopsis

The remote Windows host contains a media player that is affected by denial of service and/or a potential infoleak vulnerability.

Description

The version of VLC media player installed on the remote host with version 3.0.4. It is, therefore, affected by a denial of service and/or a potential infoleak vulnerability. (CVE-2018-19857).

Solution

Upgrade to VLC version 3.0.5 or later.

See Also

https://www.securityfocus.com/bid/106130

Plugin Details

Severity: Critical

ID: 136895

File Name: vlc_3_0_5.nasl

Version: 1.4

Type: local

Agent: windows

Family: Windows

Published: 5/27/2020

Updated: 3/8/2024

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.0

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:P

CVSS Score Source: CVE-2018-19857

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:videolan:vlc_media_player

Required KB Items: SMB/VLC/Version, installed_sw/VLC media player

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 12/5/2018

Vulnerability Publication Date: 12/5/2018

Reference Information

CVE: CVE-2018-19857

BID: 106130