ALT-PU-2018-1211-1
Closed vulnerabilities
BDU:2017-01634
Уязвимость кодека avcodec медиаплеера VideoLAN Media Player, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
BDU:2019-04182
Уязвимость библиотеки plugins\codec\libflac_plugin.dll программы-медиапроигрывателя VideoLAN VLC, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
Modified: 2025-04-20
CVE-2017-10699
avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, allows out-of-bounds heap memory write due to calling memcpy() with a wrong size, leading to a denial of service (application crash) or possibly code execution.
Modified: 2025-04-20
CVE-2017-8310
Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file.
- http://git.videolan.org/?p=vlc/vlc-2.2.git%3Ba=blobdiff%3Bf=modules/codec/subsdec.c%3Bh=addd8c71f30d53558fffd19059b374be45cf0f8e%3Bhp=1b4276e299a2a6668047231d29ac705ae93076ba%3Bhb=7cac839692ab79dbfe5e4ebd4c4e37d9a8b1b328%3Bhpb=3477dba3d506de8d95bccef2c6b67861188f6c29
- http://www.debian.org/security/2017/dsa-3899
- http://www.securityfocus.com/bid/98638
- https://security.gentoo.org/glsa/201707-10
- http://git.videolan.org/?p=vlc/vlc-2.2.git%3Ba=blobdiff%3Bf=modules/codec/subsdec.c%3Bh=addd8c71f30d53558fffd19059b374be45cf0f8e%3Bhp=1b4276e299a2a6668047231d29ac705ae93076ba%3Bhb=7cac839692ab79dbfe5e4ebd4c4e37d9a8b1b328%3Bhpb=3477dba3d506de8d95bccef2c6b67861188f6c29
- http://www.debian.org/security/2017/dsa-3899
- http://www.securityfocus.com/bid/98638
- https://security.gentoo.org/glsa/201707-10
Modified: 2025-04-20
CVE-2017-8311
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.
- http://git.videolan.org/?p=vlc.git%3Ba=commitdiff%3Bh=775de716add17322f24b476439f903a829446eb6
- http://www.debian.org/security/2017/dsa-3899
- http://www.securityfocus.com/bid/98634
- https://security.gentoo.org/glsa/201707-10
- https://www.exploit-db.com/exploits/44514/
- http://git.videolan.org/?p=vlc.git%3Ba=commitdiff%3Bh=775de716add17322f24b476439f903a829446eb6
- http://www.debian.org/security/2017/dsa-3899
- http://www.securityfocus.com/bid/98634
- https://security.gentoo.org/glsa/201707-10
- https://www.exploit-db.com/exploits/44514/
Modified: 2025-04-20
CVE-2017-8313
Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process via a crafted subtitles file.
- http://git.videolan.org/?p=vlc/vlc-2.2.git%3Ba=commitdiff%3Bh=05b653355ce303ada3b5e0e645ae717fea39186c
- http://www.debian.org/security/2017/dsa-3899
- http://www.securityfocus.com/bid/98633
- https://security.gentoo.org/glsa/201707-10
- http://git.videolan.org/?p=vlc/vlc-2.2.git%3Ba=commitdiff%3Bh=05b653355ce303ada3b5e0e645ae717fea39186c
- http://www.debian.org/security/2017/dsa-3899
- http://www.securityfocus.com/bid/98633
- https://security.gentoo.org/glsa/201707-10
Modified: 2025-04-20
CVE-2017-9300
plugins\codec\libflac_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted FLAC file.
- http://code610.blogspot.com/2017/04/multiple-crashes-in-vlc-224.html
- http://www.securityfocus.com/bid/98747
- https://www.debian.org/security/2017/dsa-4045
- http://code610.blogspot.com/2017/04/multiple-crashes-in-vlc-224.html
- http://www.securityfocus.com/bid/98747
- https://www.debian.org/security/2017/dsa-4045
Modified: 2025-04-20
CVE-2017-9301
plugins\audio_filter\libmpgatofixed32_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (invalid read and application crash) or possibly have unspecified other impact via a crafted file.
