Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-8313

Опубликовано: 23 мая 2017
Источник: debian
EPSS Низкий

Описание

Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process via a crafted subtitles file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
vlcfixed2.2.5-1package
vlcend-of-lifewheezypackage

Примечания

  • https://git.videolan.org/?p=vlc/vlc-2.2.git;a=commitdiff;h=05b653355ce303ada3b5e0e645ae717fea39186c

EPSS

Процентиль: 56%
0.00338
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process via a crafted subtitles file.

CVSS3: 5.5
nvd
больше 8 лет назад

Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process via a crafted subtitles file.

CVSS3: 5.5
github
больше 3 лет назад

Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process via a crafted subtitles file.

EPSS

Процентиль: 56%
0.00338
Низкий