Logo
vulnerabilityCVE-2024-46461
Name
CVE-2024-46461
Source
NVD ( link)Debian ( link)
Description
VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
vlc
Patched

Vulnerability Ratings#


8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.0.23
Not Affected
buildroot
master
3.0.23
Not Affected
yocto
kirkstone
3.0.17.4
Not Affected
yocto
master
3.0.23
Not Affected

Resolved with patches#


vlc (yocto:scarthgap)

#
Title
Author
Resolve
1
mms: fix potential integer overflow
Thomas Guillem <thomas@gllm.fr>
CVE-2024-46461