Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-8310

Опубликовано: 23 мая 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 5.5

Описание

Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file.

РелизСтатусПримечание
devel

not-affected

esm-apps/xenial

released

2.2.2-5ubuntu0.16.04.3
esm-infra-legacy/trusty

DNE

trusty/esm was not-affected [2.1.6-0ubuntu14.04.3]
precise/esm

DNE

trusty

released

2.1.6-0ubuntu14.04.3
trusty/esm

released

2.1.6-0ubuntu14.04.3
upstream

needs-triage

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

xenial

released

2.2.2-5ubuntu0.16.04.3

Показывать по

Ссылки на источники

EPSS

Процентиль: 57%
0.00354
Низкий

4.3 Medium

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
больше 8 лет назад

Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file.

CVSS3: 5.5
debian
больше 8 лет назад

Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due ...

CVSS3: 5.5
github
больше 3 лет назад

Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file.

EPSS

Процентиль: 57%
0.00354
Низкий

4.3 Medium

CVSS2

5.5 Medium

CVSS3