CVE-2017-8311: Buffer Overflow
Published May 23, 2017
·Updated
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.
Affected Software
1 affected component
Videolan VLC Media Player<=2.2.4
Remediation
Event History
May 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-8311?
CVE-2017-8311 is classified as a critical vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2017-8311?
To fix CVE-2017-8311, upgrade VLC media player to version 2.2.5 or later.
3
What software is affected by CVE-2017-8311?
CVE-2017-8311 affects VLC media player versions prior to 2.2.5.
4
What type of vulnerability is CVE-2017-8311?
CVE-2017-8311 is a heap-based buffer overflow vulnerability.
5
How can attackers exploit CVE-2017-8311?
Attackers can exploit CVE-2017-8311 by crafting malicious subtitles files that trigger the vulnerability.