An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade vlc | Jun 16, 2020 | May 15, 2020 |
| Debian | — | Upgrade vlc | May 29, 2020 | May 15, 2020 |
| Gentoo Linux | — | Upgrade media-video/vlc. | Jun 15, 2020 | May 15, 2020 |
| Ubuntu | — | Upgrade vlc (Ubuntu Pro)Upgrade vlc-plugin-access-extra (Ubuntu Pro)Upgrade vlc-plugin-access-extraUpgrade vlc | Jun 21, 2023 | May 15, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub