Integer Overflow Vulnerability in VNC Module of VideoLAN VLC Media Player
CVE-2022-41325
7.8HIGH
Summary
The VNC module in VideoLAN VLC Media Player contains an integer overflow flaw that can be exploited when a user is deceived into loading a malicious playlist or connecting to an untrusted VNC server. This condition could potentially lead to application crashes or, under certain circumstances, remote code execution. Users of affected versions, particularly those prior to 3.0.17.4, are advised to remain vigilant and update their software to mitigate risk.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved