Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.812504
Kategorie:Denial of Service
Titel:VLC Media Player 'MP4 Demux Module' DoS Vulnerability - Windows
Zusammenfassung:VLC media player is prone to a denial of service vulnerability.
Beschreibung:Summary:
VLC media player is prone to a denial of service vulnerability.

Vulnerability Insight:
The flaw is due to a type conversion error
in 'modules/demux/mp4/libmp4.c' in the MP4 demux module leading to an invalid
free, because the type of a box may be changed between a read operation and a
free operation.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to cause a denial-of-service condition. Given the nature of this
issue, attackers may also be able to execute arbitrary code, but this has not
been confirmed.

Affected Software/OS:
VideoLAN VLC media player 2.2.8 and prior
on Windows.

Solution:
Update to version 3.0.1 or later

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2017-17670
BugTraq ID: 102214
http://www.securityfocus.com/bid/102214
Debian Security Information: DSA-4203 (Google Search)
https://www.debian.org/security/2018/dsa-4203
http://openwall.com/lists/oss-security/2017/12/15/1
http://www.securitytracker.com/id/1040938
CopyrightCopyright (C) 2017 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.