Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-8310

Опубликовано: 23 мая 2017
Источник: debian
EPSS Низкий

Описание

Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
vlcfixed2.2.5.1-1~deb9u1package
vlcend-of-lifewheezypackage

Примечания

  • https://git.videolan.org/?p=vlc/vlc-2.2.git;a=commit;h=7cac839692ab79dbfe5e4ebd4c4e37d9a8b1b328

EPSS

Процентиль: 57%
0.00354
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file.

CVSS3: 5.5
nvd
больше 8 лет назад

Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file.

CVSS3: 5.5
github
больше 3 лет назад

Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file.

EPSS

Процентиль: 57%
0.00354
Низкий