First published: Fri Jan 24 2020(Updated: )
The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to trigger an unintended zero-size malloc and conduct buffer overflow attacks, and consequently execute arbitrary code, via a box size of 7.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Videolan Vlc Media Player | <2.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9628 is a vulnerability in VideoLAN VLC media player that allows remote attackers to conduct buffer overflow attacks and execute arbitrary code.
CVE-2014-9628 allows remote attackers to trigger an unintended zero-size malloc, leading to buffer overflow attacks and arbitrary code execution.
The severity of CVE-2014-9628 is high, with a CVSS score of 7.8.
This vulnerability can be exploited by sending a malicious payload with a specific box size parameter to the MP4_ReadBox_String function in VLC media player.
To fix CVE-2014-9628, update your VideoLAN VLC media player to version 2.1.6 or above.