8.8
CVSSv3

CVE-2017-17670

Published: 15/12/2017 Updated: 26/04/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

In VideoLAN VLC media player up to and including 2.2.8, there is a type conversion vulnerability in modules/demux/mp4/libmp4.c in the MP4 demux module leading to a invalid free, because the type of a box may be changed between a read operation and a free operation.

Vulnerable Product Search on Vulmon Subscribe to Product

videolan vlc media player

debian debian linux 9.0

Vendor Advisories

Hans Jerry Illikainen discovered a type conversion vulnerability in the MP4 demuxer of the VLC media player, which could result in the execution of arbitrary code if a malformed media file is played This update upgrades VLC in stretch to the new 3x release series (as security fixes couldn't be sensibly backported to the 2x series) In addition t ...