ALT-PU-2020-3565-1
Closed vulnerabilities
Published: 2021-01-09
BDU:2021-03626
Уязвимость функции EbmlTypeDispatcher::send медиаплеера VLC Media Player, связанная с записью за границами буфера, позволяющая нарушителю получить доступ к конфиденциальной информации или вызвать отказ в обслуживании
Severity: HIGH (8.8)
Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
Published: 2021-01-08
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2020-26664
A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.
Severity: HIGH (7.8)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
- http://videolan.com
- http://videolan.com
- http://vlc.com
- http://vlc.com
- https://gist.githubusercontent.com/henices/db11664dd45b9f322f8514d182aef5ea/raw/d56940c8bf211992bf4f3309a85bb2b69383e511/CVE-2020-26664.txt
- https://gist.githubusercontent.com/henices/db11664dd45b9f322f8514d182aef5ea/raw/d56940c8bf211992bf4f3309a85bb2b69383e511/CVE-2020-26664.txt
- [debian-lts-announce] 20220610 [SECURITY] [DLA 3050-1] vlc security update
- [debian-lts-announce] 20220610 [SECURITY] [DLA 3050-1] vlc security update
- GLSA-202101-37
- GLSA-202101-37
- DSA-4834
- DSA-4834