CVE-2013-3564

NameCVE-2013-3564
DescriptionThe web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view directory listings via the 'dir' command or issue other commands without authenticating.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
vlc (PTS)jessie, jessie (lts)2.2.7-1~deb8u1fixed
stretch (security)3.0.12-0+deb9u1fixed
stretch (lts), stretch3.0.21-0+deb9u1fixed
buster, buster (lts)3.0.21-0+deb10u1fixed
buster (security)3.0.20-0+deb10u1fixed
bullseye (security), bullseye3.0.21-0+deb11u1fixed
bookworm (security), bookworm3.0.21-0+deb12u1fixed
sid, trixie3.0.21-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
vlcsourcewheezy(unfixed)end-of-life
vlcsource(unstable)2.0.7-1

Notes

https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=18864

Search for package or bug name: Reporting problems