Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-13428

Опубликовано: 08 июн. 2020
Источник: debian
EPSS Низкий

Описание

A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
vlcfixed3.0.11-1package
vlcend-of-lifejessiepackage

Примечания

  • https://github.com/videolan/vlc-3.0/releases/tag/3.0.11

  • https://git.videolan.org/?p=vlc/vlc-3.0.git;a=commit;h=d5c43c21c747ff30ed19fcca745dea3481c733e0

EPSS

Процентиль: 91%
0.0692
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 5 лет назад

A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file.

CVSS3: 7.8
nvd
больше 5 лет назад

A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file.

CVSS3: 7.8
github
больше 3 лет назад

A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player through 3.2.8 for iOS, and through 3.0.10 for macOS, allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file.

CVSS3: 6.3
fstec
больше 5 лет назад

Уязвимость функции hxxx_AnnexB_to_xVC() программы-медиапроигрывателя Videolan VLC, позволяющая нарушителю выполнить произвольный код

suse-cvrf
около 5 лет назад

Security update for vlc

EPSS

Процентиль: 91%
0.0692
Низкий