Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-8311

Опубликовано: 23 мая 2017
Источник: debian
EPSS Низкий

Описание

Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
vlcfixed2.2.5-1package
vlcend-of-lifewheezypackage

Примечания

  • https://git.videolan.org/?p=vlc.git;a=commitdiff;h=775de716add17322f24b476439f903a829446eb6

EPSS

Процентиль: 92%
0.0789
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.

CVSS3: 7.8
nvd
больше 8 лет назад

Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.

CVSS3: 7.8
github
больше 3 лет назад

Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.

EPSS

Процентиль: 92%
0.0789
Низкий