Your submission was sent successfully! Close

CVE-2017-8310

Published: 23 May 2017

Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file.

Priority

Medium

CVSS 3 base score: 5.5

Status

Package Release Status
vlc
Launchpad, Ubuntu, Debian
precise Does not exist

trusty Does not exist
(trusty was released [2.1.6-0ubuntu14.04.3])
upstream Needs triage

xenial
Released (2.2.2-5ubuntu0.16.04.3)
yakkety Ignored
(reached end-of-life)
zesty
Released (2.2.4-14ubuntu2.1)