Name
vlc
Version
3.0.17.4
Type
library
Description
-
Licenses
GPL-2.0-only
PURL
-
CPE
cpe:2.3:*:videolan:vlc_media_player:3.0.17.4:*:*:*:*:*:*:*
Other Versions#
Patches#
#
Title
Author
Resolve
1
Patch #1
Tim Orling <TicoTimo@gmail.com>
2
Use packageconfig to detect mmal support
Khem Raj <raj.khem@gmail.com>
3
linux/thread: Use SYS_futex instead of __NR_futex
Khem Raj <raj.khem@gmail.com>
4
Patch #4
Tim Orling <TicoTimo@gmail.com>
5
Patch #5
Tim Orling <TicoTimo@gmail.com>
6
include <limits> header
Khem Raj <raj.khem@gmail.com>
Vulnerabilities#
Name
Analysis
Description
Exploitable
Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length.
Exploitable
Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption.
Exploitable
An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.