CVE-2015-5949: Buffer Overflow
Published Aug 25, 2015
·Updated
VideoLAN VLC media player 2.2.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted 3GP file, which triggers the freeing of arbitrary pointers.
Affected Software
1 affected component
Videolan VLC Media Player<=2.2.1
Event History
Aug 25, 2015
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5949?
CVE-2015-5949 has a high severity rating due to the potential for denial of service and arbitrary code execution.
2
How do I fix CVE-2015-5949?
To fix CVE-2015-5949, update VLC media player to a version later than 2.2.1 that addresses this vulnerability.
3
What kind of attack does CVE-2015-5949 enable?
CVE-2015-5949 enables remote attackers to cause a denial of service or possibly execute arbitrary code through a crafted 3GP file.
4
Which versions of VLC media player are affected by CVE-2015-5949?
VLC media player versions up to and including 2.2.1 are affected by CVE-2015-5949.
5
Can CVE-2015-5949 be exploited remotely?
Yes, CVE-2015-5949 can be exploited remotely by delivering a specially crafted 3GP file to the victim.