Buffer Overflow Vulnerability in VideoLAN VLC Media Player
CVE-2014-9625

7.8HIGH

Key Information:

Vendor
Videolan
Vendor
CVE Published:
24 January 2020

Summary

A flaw exists in the GetUpdateFile function within the Updater component of VideoLAN's VLC media player prior to version 2.1.6, which improperly casts a 64-bit integer to a 32-bit integer. This integer truncation vulnerability can be exploited by attackers to trigger buffer overflow attacks. By crafting a malicious update status file, attackers could execute arbitrary code in the context of the application, posing a significant security risk for users of affected versions.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.