vendor:
VLC media player
by:
Francis Provencher
7,5
CVSS
HIGH
Heap Memory Corruption
119
CWE
Product Name: VLC media player
Affected Version From: 2.2.1
Affected Version To: 2.2.1
Patch Exists: YES
Related CWE: N/A
CPE: vlc_media_player
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2016
VLC Media Player Heap Memory Corruption Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of VLC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. An heap memory corruption occured when VLC parsed an malformed MPEG-4 file that contain an invalid Sample Table and Sample Descriptiion Box.
Mitigation:
Update to the latest version of VLC media player