CVE-2018-19857
PoC —CVSS 3.0
9.1 critical
EPSS
4%p90
Published
()
Modified
Description
The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies in CAF files, because a ReadKukiChunk() cast converts a return value to an unsigned int even if that value is negative. This could result in a denial of service and/or a potential infoleak.
In the news0 stories
No ingested article mentions this CVE yet.