Heap-Based Buffer Overflow Vulnerability in VideoLAN VLC Media Player
CVE-2020-13428
7.8HIGH
What is CVE-2020-13428?
A vulnerability exists in the hxxx_AnnexB_to_xVC function located within the modules/packetizer/hxxx_nal.c file of VideoLAN's VLC media player, specifically affecting versions prior to 3.0.11 on macOS and iOS platforms. This vulnerability can be exploited by remote attackers through specially crafted H.264 Annex-B video files, such as those with an .avi extension. Successful exploitation may lead to application crashes or could potentially allow attackers to execute arbitrary code on the affected systems.