The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies in CAF files, because a ReadKukiChunk() cast converts a return value to an unsigned int even if that value is negative. This could result in a denial of service and/or a potential infoleak.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade vlc | Jan 13, 2019 | Dec 5, 2018 |
| Suse | — | Upgrade aom-toolsUpgrade libaom0Upgrade libvlc5Upgrade libaom-devel-docUpgrade vlc-jackUpgrade vlc-langUpgrade vlcUpgrade libaom-develUpgrade vlc-develUpgrade libvlccore9Upgrade vlc-qtUpgrade vlc-noxUpgrade vlc-vdpauUpgrade vlc-codec-gstreamerUpgrade libaom0-64bit | Aug 9, 2019 | Dec 5, 2018 |
| Ubuntu | — | Upgrade vlc | Jul 26, 2019 | Dec 5, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub