Impact
Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory‑safety vulnerability that can be reached when processing media from an attacker‑controlled network source. The flaw, which involves a buffer overrun (CWE‑125) and an improper conversion (CWE‑170), may disclose a limited, layout‑dependent portion of the VLC process memory. Exploitation requires user interaction, such as opening a malicious media file or stream.
Affected Systems
VideoLAN VLC media player versions 3.0.0 through 3.0.23 are affected. The vulnerability is present in builds that include network source handling, such as those compiled with the RTSP module enabled. Exposure depends on the build configuration and is confined to the process memory of the player.
Risk and Exploitability
The CVSS base score is 5.3, reflecting medium severity, while the EPSS score indicates a very low but non‑zero likelihood of exploitation (<1 %). The vulnerability is not listed in CISA’s KEV catalog. Because the exploitation path requires user interaction and an attacker‑controlled network source, the risk is primarily tied to untrusted media being opened by the client.
OpenCVE Enrichment
Debian DSA