CVE-2016-3941: Buffer Overflow
Published Apr 18, 2016
·Updated
Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF."
Affected Software
2 affected components
Videolan VLC Media Player<=2.1.6
Canonical Ubuntu Linux=14.04
Event History
Apr 18, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3941?
CVE-2016-3941 has a severity rating that can lead to denial of service through a buffer overflow in VLC media player.
2
How do I fix CVE-2016-3941?
To fix CVE-2016-3941, update VLC media player to version 2.2.0 or later.
3
Which versions of VLC media player are affected by CVE-2016-3941?
VLC media player versions prior to 2.2.0, specifically up to 2.1.6, are affected by CVE-2016-3941.
4
Is Ubuntu Linux 14.04 affected by CVE-2016-3941?
Yes, Ubuntu Linux 14.04 is affected by CVE-2016-3941 if it is running the vulnerable version of VLC media player.
5
What type of attack does CVE-2016-3941 facilitate?
CVE-2016-3941 allows remote attackers to crash the VLC media player by exploiting a crafted wav file.