First published: Fri Dec 15 2017(Updated: )
In VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerability in modules/demux/mp4/libmp4.c in the MP4 demux module leading to a invalid free, because the type of a box may be changed between a read operation and a free operation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/vlc | 3.0.17.4-0+deb10u1 3.0.17.4-0+deb10u2 3.0.18-0+deb11u1 3.0.18-2 3.0.19-1 | |
VideoLAN VLC media player | <=2.2.8 | |
Debian GNU/Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17670 is a type conversion vulnerability in VideoLAN VLC media player through 2.2.8, leading to an invalid free operation.
CVE-2017-17670 has a severity value of 8.8, which is considered high.
The affected software includes VideoLAN VLC media player versions through 2.2.8 and Debian Linux version 9.0.
To fix CVE-2017-17670, update VideoLAN VLC media player to version 3.0.17.4-0+deb10u1 or later, or Debian Linux to version 9.0 or later.
More information about CVE-2017-17670 can be found at the following references: [1] [2] [3]