Code Flow Manipulation Vulnerability in VLC Media Player by VideoLAN
CVE-2019-18278

7.8HIGH

Key Information:

Vendor
Videolan
Vendor
CVE Published:
23 October 2019

Summary

A vulnerability in VLC Media Player 3.0.8 allows for code flow manipulation due to a faulting address when executed with libqt on Windows. This flaw results in potential security risks, as maliciously crafted data may influence program behavior. The VideoLAN security team has noted that they have yet to receive reports or reproduction steps for this issue, highlighting the importance of user awareness and security practices.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.