CVE-2017-17670: Use After Free
In VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerability in modules/demux/mp4/libmp4.c in the MP4 demux module leading to a invalid free, because the type of a box may be changed between a read operation and a free operation.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-17670?
CVE-2017-17670 is a type conversion vulnerability in VideoLAN VLC media player through 2.2.8, leading to an invalid free operation.
How severe is CVE-2017-17670?
CVE-2017-17670 has a severity value of 8.8, which is considered high.
What software is affected by CVE-2017-17670?
The affected software includes VideoLAN VLC media player versions through 2.2.8 and Debian Linux version 9.0.
How can I fix CVE-2017-17670?
To fix CVE-2017-17670, update VideoLAN VLC media player to version 3.0.17.4-0+deb10u1 or later, or Debian Linux to version 9.0 or later.
Where can I find more information about CVE-2017-17670?
More information about CVE-2017-17670 can be found at the following references: [1] [2] [3]