ZeroHour

CVE-2018-19857

PoC
CVSS 3.0
9.1 critical
EPSS
4%p90
Published
()
Modified
Description

The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies in CAF files, because a ReadKukiChunk() cast converts a return value to an unsigned int even if that value is negative. This could result in a denial of service and/or a potential infoleak.

Vendors
videolandebian
Products
vlc media player, debian linux
Weakness
CWE-824
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.