Integer Overflow Vulnerability in VNC Module of VideoLAN VLC Media Player
CVE-2022-41325

7.8HIGH

Key Information:

Vendor
Videolan
Vendor
CVE Published:
6 December 2022

Summary

The VNC module in VideoLAN VLC Media Player contains an integer overflow flaw that can be exploited when a user is deceived into loading a malicious playlist or connecting to an untrusted VNC server. This condition could potentially lead to application crashes or, under certain circumstances, remote code execution. Users of affected versions, particularly those prior to 3.0.17.4, are advised to remain vigilant and update their software to mitigate risk.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.