Описание
The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds properly. As a result, a heap-based buffer over-read can be triggered via a crafted .ogg file.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 3.0.8-0ubuntu18.04.1 |
| devel | not-affected | 3.0.8-2 |
| disco | released | 3.0.8-0ubuntu19.04.1 |
| eoan | not-affected | 3.0.8-2 |
| esm-apps/bionic | released | 3.0.8-0ubuntu18.04.1 |
| esm-apps/focal | not-affected | 3.0.8-2 |
| esm-apps/jammy | not-affected | 3.0.8-2 |
| esm-apps/noble | not-affected | 3.0.8-2 |
| esm-apps/xenial | needed | |
| focal | not-affected | 3.0.8-2 |
Показывать по
EPSS
6.8 Medium
CVSS2
7.8 High
CVSS3
Связанные уязвимости
The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds properly. As a result, a heap-based buffer over-read can be triggered via a crafted .ogg file.
The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC ...
The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds properly. As a result, a heap-based buffer over-read can be triggered via a crafted .ogg file.
Уязвимость функции xiph_SplitHeaders программы-медиапроигрывателя VideoLAN VLC, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
EPSS
6.8 Medium
CVSS2
7.8 High
CVSS3