Buffer Overflow Vulnerability in VideoLAN VLC Media Player
CVE-2014-9625
7.8HIGH
What is CVE-2014-9625?
A flaw exists in the GetUpdateFile function within the Updater component of VideoLAN's VLC media player prior to version 2.1.6, which improperly casts a 64-bit integer to a 32-bit integer. This integer truncation vulnerability can be exploited by attackers to trigger buffer overflow attacks. By crafting a malicious update status file, attackers could execute arbitrary code in the context of the application, posing a significant security risk for users of affected versions.