VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.videolan.org/security/sb-vlc3021.html |
History
Wed, 25 Sep 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Videolan
Videolan vlc Media Player |
|
Weaknesses | CWE-122 | |
CPEs | cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:*:*:* | |
Vendors & Products |
Videolan
Videolan vlc Media Player |
|
Metrics |
cvssV3_1
|
Wed, 25 Sep 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-09-25T00:00:00
Updated: 2024-09-25T15:39:36.371Z
Reserved: 2024-09-11T00:00:00
Link: CVE-2024-46461
Vulnrichment
Updated: 2024-09-25T15:39:31.700Z
NVD
Status : Awaiting Analysis
Published: 2024-09-25T15:15:14.567
Modified: 2024-09-26T13:32:02.803
Link: CVE-2024-46461
Redhat
No data.