[Bug 1163110] New: VUL-1: CVE-2013-3564: vlc: The web interface in no access control which allows remote attackers to view directory listings via the 'dir' command or issue other commands without authenticating
http://bugzilla.opensuse.org/show_bug.cgi?id=1163110 Bug ID: 1163110 Summary: VUL-1: CVE-2013-3564: vlc: The web interface in no access control which allows remote attackers to view directory listings via the 'dir' command or issue other commands without authenticating Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.1 Hardware: Other URL: https://smash.suse.de/issue/252583/ OS: Other Status: NEW Severity: Minor Priority: P5 - None Component: Security Assignee: security-team@suse.de Reporter: rfrohl@suse.com QA Contact: security-team@suse.de Found By: Security Response Team Blocker: --- CVE-2013-3564 The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view directory listings via the 'dir' command or issue other commands without authenticating. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-3564 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3564 https://www3.trustwave.com/spiderlabs/advisories/TWSL2013-007.txt -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1163110 http://bugzilla.opensuse.org/show_bug.cgi?id=1163110#c1 Robert Frohl <rfrohl@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED Resolution|--- |INVALID --- Comment #1 from Robert Frohl <rfrohl@suse.com> --- already fixed, version are 3.0.7.1 (Leap) or 3.0.8 (Tumbleweed) -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com