PT-2015-3379 · Videolan+1 · Vlc Media Player+1

Fabian Yamaguchi

·

Published

2015-01-20

·

Updated

2020-01-29

·

CVE-2014-9628

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VideoLAN VLC media player versions prior to 2.1.6
Description The issue is related to errors in checking the length of string containers in the MP4 demultiplexer of the VideoLAN VLC media player. Exploitation of this issue may allow a remote attacker to execute arbitrary code or cause a denial of service via a specially crafted .MP4 file. The MP4 ReadBox String function is specifically vulnerable, allowing remote attackers to trigger an unintended zero-size malloc and conduct buffer overflow attacks.
Recommendations For versions prior to 2.1.6, update to version 2.1.6 or later to resolve the issue. As a temporary workaround, consider avoiding the use of .MP4 files from untrusted sources until the update is applied.

Fix

RCE

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1261
BDU:2019-03982
CVE-2014-9628
DSA-3150-1
MGASA-2015-0053

Affected Products

Alt Linux
Vlc Media Player