An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade vlc | Aug 22, 2024 | Dec 6, 2022 |
| Debian | — | Upgrade vlc | Dec 5, 2022 | Dec 5, 2022 |
| Gentoo Linux | — | Upgrade media-video/vlc. | Sep 23, 2024 | Dec 6, 2022 |
| Suse | — | Upgrade vlc-codec-gstreamerUpgrade vlc-qtUpgrade vlc-develUpgrade libvlc5Upgrade vlcUpgrade vlc-langUpgrade vlc-noxUpgrade vlc-opencvUpgrade vlc-vdpauUpgrade vlc-jackUpgrade libvlccore9 | Dec 28, 2022 | Dec 6, 2022 |
| Ubuntu | — | Upgrade vlc-plugin-access-extraUpgrade vlc (Ubuntu Pro)Upgrade vlc-plugin-access-extra (Ubuntu Pro)Upgrade vlc | Jun 21, 2023 | Dec 6, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub