vendor:
VLC Player
by:
Veysel HATAS
7.5
CVSS
HIGH
Write Access Violation
CWE
Product Name: VLC Player
Affected Version From: 2.1.2005
Affected Version To:
Patch Exists: YES
Related CWE: CVE-2014-9598
CPE:
Platforms Tested: Windows XP SP3
2014
VLC Player 2.1.5 Write Access Violation Vulnerability
VLC Media Player contains a flaw that is triggered as user-supplied input is not properly sanitized when handling a specially crafted M2V file. This may allow a context-dependent attacker to corrupt memory and potentially execute arbitrary code.