CVE-2017-9300: Buffer Overflow
Published May 29, 2017
·Updated
plugins\codec\libflacplugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted FLAC file.
Affected Software
2 affected componentsFixes available
debian/vlc
3.0.17.4-0+deb10u13.0.17.4-0+deb10u23.0.18-0+deb11u13.0.18-23.0.19-1
Videolan VLC Media Player<=2.2.4
Event History
May 29, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9300?
CVE-2017-9300 is classified as a moderate severity vulnerability due to its potential to cause denial of service through heap corruption.
2
How do I fix CVE-2017-9300?
To fix CVE-2017-9300, update VideoLAN VLC media player to version 3.0.17.4 or later.
3
Which versions of VLC media player are affected by CVE-2017-9300?
CVE-2017-9300 affects VLC media player versions up to 2.2.4.
4
What impact can CVE-2017-9300 have on users?
CVE-2017-9300 can cause application crashes and heap corruption, leading to a denial of service.
5
Are there any known exploits for CVE-2017-9300?
As of now, there are no publicly disclosed exploits specifically targeting CVE-2017-9300.