6.8
CVSSv2

CVE-2020-13428

Published: 08/06/2020 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player prior to 3.0.11 for macOS/iOS allows remote malicious users to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

videolan vlc media player

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

A vulnerability was discovered in the VLC media player, which could result in the execution of arbitrary code or denial of service if a malformed video file is opened For the oldstable distribution (stretch), this problem has been fixed in version 3011-0+deb9u1 For the stable distribution (buster), this problem has been fixed in version 3011- ...