CVE-2017-10699: Critical severity Videolan VLC Media Player vulnerability
Published Jun 30, 2017
·Updated
avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, allows out-of-bounds heap memory write due to calling memcpy() with a wrong size, leading to a denial of service (application crash) or possibly code execution.
Affected Software
10 affected componentsFixes available
debian/vlc
3.0.17.4-0+deb10u13.0.17.4-0+deb10u23.0.18-0+deb11u13.0.18-23.0.19-1
Videolan VLC Media Player=2.2.0
Videolan VLC Media Player=2.2.1
Videolan VLC Media Player=2.2.2
Videolan VLC Media Player=2.2.3
Videolan VLC Media Player=2.2.4
Videolan VLC Media Player=2.2.5
Videolan VLC Media Player=2.2.5.1
Videolan VLC Media Player=2.2.6
Videolan VLC Media Player=2.2.7
Event History
Jun 30, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10699?
The severity of CVE-2017-10699 is assessed as critical, with a score of 9.8.
2
How do I fix CVE-2017-10699?
To fix CVE-2017-10699, update VLC media player to version 3.0.17.4 or later.
3
What vulnerabilities does CVE-2017-10699 exploit?
CVE-2017-10699 exploits an out-of-bounds heap memory write due to incorrect parameters in memcpy().
4
Which versions of VLC media player are affected by CVE-2017-10699?
Affected versions include VLC media player 2.2.0 through 2.2.7.
5
What is the potential impact of CVE-2017-10699?
The potential impact of CVE-2017-10699 includes denial of service or possible remote code execution.