CVE-2014-9630: Buffer Overflow
The rtppacketizexiphconfig function in modules/streamout/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a stack-allocation approach with a size determined by arbitrary input data, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted length value.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2014-9630?
CVE-2014-9630 is a vulnerability in VideoLAN VLC media player before 2.1.6 that allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified impact.
How severe is CVE-2014-9630?
CVE-2014-9630 has a severity rating of 7.8, which is considered high.
How can CVE-2014-9630 be fixed?
To fix CVE-2014-9630, it is recommended to update VideoLAN VLC media player to version 2.1.6 or later.
What is CWE-119?
CWE-119 is a vulnerability type related to memory corruption.
Where can I find more information about CVE-2014-9630?
More information about CVE-2014-9630 can be found at the following references: [1](http://openwall.com/lists/oss-security/2015/01/20/5), [2](https://github.com/videolan/vlc/commit/204291467724867b79735c0ee3aeb0dbc2200f97), [3](https://www.videolan.org/security/sa1501.html).