6.8
CVSSv2

CVE-2017-9300

Published: 29/05/2017 Updated: 23/11/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

plugins\codec\libflac_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote malicious users to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted FLAC file.

Vulnerable Product Search on Vulmon Subscribe to Product

videolan vlc media player

Vendor Advisories

Several vulnerabilities have been found in VLC, the VideoLAN project's media player Processing malformed media files could lead to denial of service and potentially the execution of arbitrary code For the oldstable distribution (jessie), these problems have been fixed in version 227-1~deb8u1 For the stable distribution (stretch), these problem ...
It was discovered that plugins\codec\libflac_pluginso in VideoLAN VLC media player before 227 allows remote attackers to cause a heap corruption and application crash leading to denial of service or possibly execution of arbitrary code via a crafted FLAC file ...