The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies in CAF files, because a ReadKukiChunk() cast converts a return value to an unsigned int even if that value is negative. This could result in a denial of service and/or a potential infoleak.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade vlc | Jan 13, 2019 | Dec 5, 2018 |
| Suse | — | Upgrade libaom-devel-docUpgrade vlc-jackUpgrade vlc-langUpgrade libvlc5Upgrade vlcUpgrade aom-toolsUpgrade libaom0Upgrade libaom-develUpgrade vlc-noxUpgrade vlc-qtUpgrade vlc-vdpauUpgrade libaom0-64bitUpgrade libvlccore9Upgrade vlc-codec-gstreamerUpgrade vlc-devel | Aug 9, 2019 | Dec 5, 2018 |
| Ubuntu | — | Upgrade vlc | Jul 26, 2019 | Dec 5, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub