7.5
CVSSv2

CVE-2017-10699

Published: 30/06/2017 Updated: 23/11/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x prior to 2017-06-29, allows out-of-bounds heap memory write due to calling memcpy() with a wrong size, leading to a denial of service (application crash) or possibly code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

videolan vlc media player 2.2.7

videolan vlc media player 2.2.4

videolan vlc media player 2.2.3

videolan vlc media player 2.2.5

videolan vlc media player 2.2.5.1

videolan vlc media player 2.2.6

videolan vlc media player 2.2.0

videolan vlc media player 2.2.2

videolan vlc media player 2.2.1

Vendor Advisories

Several vulnerabilities have been found in VLC, the VideoLAN project's media player Processing malformed media files could lead to denial of service and potentially the execution of arbitrary code For the oldstable distribution (jessie), these problems have been fixed in version 227-1~deb8u1 For the stable distribution (stretch), these problem ...
It was discovered that avcodec 22x, as used in VideoLAN VLC media player before 227, allows out-of-bounds heap memory write due to calling memcpy() with a wrong size, leading to a denial of service (application crash) or possibly code execution ...