CVE-2017-8310: Medium severity vlc media player vulnerability
Published May 23, 2017
·Updated
Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file.
Affected Software
6 affected components
Videolan VLC Media Player=2.2.0
Videolan VLC Media Player=2.2.1
Videolan VLC Media Player=2.2.2
Videolan VLC Media Player=2.2.3
Videolan VLC Media Player=2.2.4
Videolan VLC Media Player=2.2.5
Event History
May 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-8310?
CVE-2017-8310 has a moderate severity level due to the potential for denial of service caused by a heap out-of-bound read.
2
Which versions of VLC media player are affected by CVE-2017-8310?
CVE-2017-8310 affects VLC media player versions 2.2.0 through 2.2.5.
3
How do I fix CVE-2017-8310?
To fix CVE-2017-8310, upgrade to a newer version of VLC media player that addresses this vulnerability.
4
What types of attacks are possible with CVE-2017-8310?
CVE-2017-8310 allows attackers to read data beyond allocated memory, potentially leading to a process crash.
5
What component of VLC is impacted by CVE-2017-8310?
CVE-2017-8310 impacts the CreateHtmlSubtitle function in VLC's subtitle processing.