All errata/sisyphus/ALT-PU-2023-8665-1
ALT-PU-2023-8665-1

Package update vlc in branch sisyphus

Version3.0.19-alt1
Published2023-10-24
Max severityHIGH
Severity:

Closed issues (1)

CVE-2023-46814
HIGH7.8

A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM.

Published: 2023-11-22Modified: 2024-11-21
CVSS 3.xHIGH 7.8
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H