First published: Tue May 23 2017(Updated: )
Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a crafted subtitles file.
Credit: cve@checkpoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
VLC media player | <2.2.6 | |
Debian | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8312 has been assigned a medium severity level due to its potential for information disclosure through heap out-of-bounds read.
To fix CVE-2017-8312, update VLC Media Player to a version higher than 2.2.6 or apply relevant security patches provided by your distributor.
CVE-2017-8312 affects VLC Media Player versions prior to 2.2.6 and Debian GNU/Linux version 8.0.
CVE-2017-8312 is a heap out-of-bounds read vulnerability caused by inadequate string length checking.
Yes, CVE-2017-8312 can be exploited by attackers via crafted subtitle files to read uninitialized heap data.