VideoLAN VLC media player 2.2.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted 3GP file, which triggers the freeing of arbitrary pointers.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade vlc | Aug 24, 2018 | Aug 25, 2015 |
| Debian | — | Upgrade vlc | Jul 30, 2024 | Aug 25, 2015 |
| Freebsd | — | Upgrade vlc | Dec 10, 2025 | Aug 20, 2015 |
| Gentoo Linux | — | Upgrade media-video/vlc. | Oct 30, 2017 | Aug 25, 2015 |
| Suse | — | Upgrade vlc-noX-langUpgrade libvlccore8Upgrade vlc-noxUpgrade vlc-gnomeUpgrade vlc-gnome-debuginfoUpgrade vlc-qtUpgrade vlcUpgrade libvlccore8-debuginfoUpgrade vlc-noX-debuginfoUpgrade vlc-develUpgrade vlc-debuginfoUpgrade vlc-qt-debuginfoUpgrade libvlc5-debuginfoUpgrade vlc-debugsourceUpgrade libvlc5 | Feb 17, 2016 | Aug 25, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub