PT-2018-3152 · Videolan+2 · Vlc Media Player+2
Eugene Ng
+1
·
Published
2017-06-02
·
Updated
2021-03-15
·
CVE-2018-11529
CVSS v2.0
8.3
High
| Vector | AV:A/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VideoLAN VLC media player versions 2.2.x
Description
The issue is related to a use after free vulnerability. This can be exploited by an attacker to execute arbitrary code using specially crafted mkv files. Failed attempts to exploit this issue may result in denial of service conditions.
Recommendations
For version 2.2.x, consider avoiding the use of mkv files until a patch is available. As a temporary workaround, restrict the use of potentially vulnerable functions related to mkv file processing to minimize the risk of exploitation.
Exploit
Fix
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Ubuntu
Vlc Media Player