QID 375424
Date Published: 2021-04-05
QID 375424: VideoLAN VLC NULL Dereference Vulnerability ( VideoLAN-SA-1107)
VLC is a cross-platform media player.
A remote user could create a specifically crafted file that could trigger some various issues, notably 2 read buffer overflows, and some invalid pointers being dereferenced.
Affected Versions:
VLC Prior to 1.1.11
QID Detection Logic (Authentication)
This QID Checks For Vulnerable Version Of VLC
On Successful exploitation a malicious third party could trigger either a crash of VLC or an arbitratry code execution with the privileges of the target user.
Solution
The vendor has released updates to resolve this issue. Refer to Security Advisory VideoLAN-SA-1107 to obtain additional details.
Vendor References
- VideoLAN-SA-1107 -
www.videolan.org/security/sa1107.html
CVEs related to QID 375424
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VideoLAN-SA-1107 | Windows |
|