CVE-2012-0023

critical
Published 2012-10-30 · Modified 2026-04-29
CVSS v3
CVSS v2
9.3
VIR risk
9.3

Description

Double free vulnerability in the get_chunk_header function in modules/demux/ty.c in VideoLAN VLC media player 0.9.0 through 1.1.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TiVo (TY) file.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-0023

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.videolan.org/security/sa1108.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/47325

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.1.13-1
debian debianbullseyefixed1.1.13-1
debian debianforkyfixed1.1.13-1
debian debiansidfixed1.1.13-1
debian debiantrixiefixed1.1.13-1

Application impact

VendorProductVersionsFixed
videolanvlc_media_player0.9.0
videolanvlc_media_player0.9.1
videolanvlc_media_player0.9.2
videolanvlc_media_player0.9.3
videolanvlc_media_player0.9.4
videolanvlc_media_player0.9.5
videolanvlc_media_player0.9.6
videolanvlc_media_player0.9.8a
videolanvlc_media_player0.9.9
videolanvlc_media_player0.9.9a
videolanvlc_media_player0.9.10
videolanvlc_media_player1.0.0
videolanvlc_media_player1.0.1
videolanvlc_media_player1.0.2
videolanvlc_media_player1.0.3
videolanvlc_media_player1.0.4
videolanvlc_media_player1.0.5
videolanvlc_media_player1.0.6
videolanvlc_media_player1.1.0
videolanvlc_media_player1.1.1
videolanvlc_media_player1.1.2
videolanvlc_media_player1.1.3
videolanvlc_media_player1.1.4
videolanvlc_media_player1.1.4.1
videolanvlc_media_player1.1.5
videolanvlc_media_player1.1.6
videolanvlc_media_player1.1.6.1
videolanvlc_media_player1.1.7
videolanvlc_media_player1.1.8
videolanvlc_media_player1.1.9
videolanvlc_media_player1.1.10
videolanvlc_media_player1.1.10.1
videolanvlc_media_player1.1.11
videolanvlc_media_player1.1.12

References

CWEs

CWE-399

Verify integrity in audit chain (admin only). AS-IS.