In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c that will lead to a denial of service attack.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade vlc | Nov 8, 2019 | Aug 29, 2019 |
| Debian | — | Upgrade vlc | Aug 22, 2019 | Aug 22, 2019 |
| Freebsd | — | Upgrade vlc | Aug 21, 2019 | Aug 20, 2019 |
| Gentoo Linux | — | Upgrade media-video/vlc. | Sep 9, 2019 | Aug 29, 2019 |
| Suse | — | Upgrade vlc-codec-gstreamerUpgrade vlc-jackUpgrade vlc-opencvUpgrade vlc-langUpgrade vlcUpgrade libvlc5Upgrade vlc-develUpgrade libvlccore9Upgrade vlc-qtUpgrade vlc-noxUpgrade vlc-vdpau | Apr 24, 2020 | Jul 14, 2019 |
| Ubuntu | — | Upgrade vlc | Sep 12, 2019 | Jul 14, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub