Denial of Service Vulnerability in VideoLAN VLC Media Player
CVE-2014-9630

7.8HIGH

Key Information:

Vendor
Videolan
Vendor
CVE Published:
24 January 2020

Summary

The rtp_packetize_xiph_config function in the VLC media player prior to version 2.1.6 uses stack allocation driven by user-controlled input. This flaw can be exploited by remote attackers who craft malicious length values, potentially leading to memory corruption and denial of service. Protect your systems by ensuring your software is updated to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.