An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade vlc | Aug 22, 2024 | Dec 6, 2022 |
| Debian | — | Upgrade vlc | Dec 5, 2022 | Dec 5, 2022 |
| Gentoo Linux | — | Upgrade media-video/vlc. | Sep 23, 2024 | Dec 6, 2022 |
| Suse | — | Upgrade vlc-qtUpgrade vlc-codec-gstreamerUpgrade vlc-langUpgrade libvlc5Upgrade vlcUpgrade vlc-develUpgrade libvlccore9Upgrade vlc-vdpauUpgrade vlc-jackUpgrade vlc-noxUpgrade vlc-opencv | Dec 28, 2022 | Dec 6, 2022 |
| Ubuntu | — | Upgrade vlc-plugin-access-extraUpgrade vlcUpgrade vlc (Ubuntu Pro)Upgrade vlc-plugin-access-extra (Ubuntu Pro) | Jun 21, 2023 | Dec 6, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub