PT-2023-7038 · Videolan+5 · Vlc+5

Published

2023-11-02

·

Updated

2024-05-22

·

CVE-2023-47360

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Videolan VLC versions prior to 3.0.20
Description The issue is related to an integer underflow in the GetPacket() function of the VLC media player, which can lead to an incorrect packet length. This can potentially allow a remote attacker to cause a denial of service.
Recommendations For versions prior to 3.0.20, update to version 3.0.20 or later to resolve the issue. As a temporary workaround, consider restricting access to the GetPacket() function until a patch is available.

Exploit

Fix

DoS

Integer Underflow

Weakness Enumeration

Related Identifiers

ALT-PU-2024-7134
BDU:2023-08060
CVE-2023-47360
DLA-3679-1
DSA-5545-1
MGASA-2024-0007
USN-6783-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Red Os
Ubuntu
Vlc