An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade vlc | Aug 22, 2024 | Dec 6, 2022 |
| Debian | — | Upgrade vlc | Dec 5, 2022 | Dec 5, 2022 |
| Gentoo Linux | — | Upgrade media-video/vlc. | Sep 23, 2024 | Dec 6, 2022 |
| Suse | — | Upgrade vlc-noxUpgrade vlc-opencvUpgrade libvlccore9Upgrade vlc-jackUpgrade vlc-vdpauUpgrade vlc-langUpgrade vlc-qtUpgrade vlc-codec-gstreamerUpgrade vlcUpgrade vlc-develUpgrade libvlc5 | Dec 28, 2022 | Dec 6, 2022 |
| Ubuntu | — | Upgrade vlc (Ubuntu Pro)Upgrade vlc-plugin-access-extraUpgrade vlc-plugin-access-extra (Ubuntu Pro)Upgrade vlc | Jun 21, 2023 | Dec 6, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub