{"id":"CVE-2010-2937","details":"The ReadMetaFromId3v2 function in taglib.cpp in the TagLib plugin in VideoLAN VLC media player 0.9.0 through 1.1.2 does not properly process ID3v2 tags, which allows remote attackers to cause a denial of service (application crash) via a crafted media file.","modified":"2026-04-10T03:41:21.503217Z","published":"2010-08-20T18:00:02Z","related":["openSUSE-SU-2024:10064-1"],"references":[{"type":"ADVISORY","url":"http://www.videolan.org/security/sa1004.html"},{"type":"ADVISORY","url":"http://www.vupen.com/english/advisories/2010/2087"},{"type":"WEB","url":"http://git.videolan.org/?p=vlc/vlc-1.0.git%3Ba=commit%3Bh=22a22e356c9d93993086810b2e25b59b55925b3a"},{"type":"WEB","url":"http://git.videolan.org/?p=vlc/vlc-1.1.git%3Ba=commit%3Bh=24918843e57c7962e28fcb01845adce82bed6516"},{"type":"WEB","url":"http://www.securityfocus.com/bid/42386"},{"type":"WEB","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14676"}],"schema_version":"1.7.5"}