Vulnerability CVE-2017-17670


Published: 2017-12-15

Description:
In VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerability in modules/demux/mp4/libmp4.c in the MP4 demux module leading to a invalid free, because the type of a box may be changed between a read operation and a free operation.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
VLC 2.2.8 MP4 Demux Type Conversion
hji
18.12.2017

Type:

CWE-416

(Use After Free)

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Videolan -> Vlc media player 
Debian -> Debian linux 

 References:
http://openwall.com/lists/oss-security/2017/12/15/1
http://www.securityfocus.com/bid/102214
http://www.securitytracker.com/id/1040938
https://www.debian.org/security/2018/dsa-4203

Copyright 2024, cxsecurity.com

 

Back to Top