CVE-2017-8312: Medium severity vlc media player vulnerability
Published May 23, 2017
·Updated
Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a crafted subtitles file.
Affected Software
2 affected components
Videolan VLC Media Player<2.2.6
Debian Debian Linux=8.0
Event History
May 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-8312?
CVE-2017-8312 has been assigned a medium severity level due to its potential for information disclosure through heap out-of-bounds read.
2
How do I fix CVE-2017-8312?
To fix CVE-2017-8312, update VLC Media Player to a version higher than 2.2.6 or apply relevant security patches provided by your distributor.
3
What software is affected by CVE-2017-8312?
CVE-2017-8312 affects VLC Media Player versions prior to 2.2.6 and Debian GNU/Linux version 8.0.
4
What type of vulnerability is CVE-2017-8312?
CVE-2017-8312 is a heap out-of-bounds read vulnerability caused by inadequate string length checking.
5
Can CVE-2017-8312 allow exploitation through subtitles?
Yes, CVE-2017-8312 can be exploited by attackers via crafted subtitle files to read uninitialized heap data.