ZeroHour

CVE-2017-8311

CVSS 3.0
7.8 high
EPSS
9%p95
Published
()
Modified
Description

Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.

Vendors
videolan
Products
vlc media player
Weakness
CWE-119
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.