All errata/c10f1/ALT-PU-2023-4399-2
ALT-PU-2023-4399-2

Package update vlc in branch c10f1

Version3.0.18-alt3
Published2023-07-15
Max severityHIGH
Severity:

Closed issues (2)

BDU:2022-07176
HIGH7.8

Уязвимость модуля VNC медиаплеера VLC, позволяющая нарушителю выполнить произвольный код в целевой системе

Published: 2022-12-09Modified: 2023-10-20
CVSS 3.xHIGH 7.8
CVSS:3.x/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.0HIGH 7.2
CVSS:2.0/AV:L/AC:L/Au:N/C:C/I:C/A:C
References
CVE-2022-41325
HIGH7.8

An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.

Published: 2022-12-06Modified: 2025-04-23
CVSS 3.xHIGH 7.8
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H