CVE-2017-9301: High severity Videolan VLC Media Player vulnerability
Published May 29, 2017
·Updated
plugins\audiofilter\libmpgatofixed32plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (invalid read and application crash) or possibly have unspecified other impact via a crafted file.
Affected Software
1 affected component
Videolan VLC Media Player<=2.2.4
Event History
May 29, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9301?
CVE-2017-9301 has a severity rating that allows for denial of service through application crashes.
2
How do I fix CVE-2017-9301?
To fix CVE-2017-9301, upgrade VLC media player to a version later than 2.2.4.
3
What software is affected by CVE-2017-9301?
CVE-2017-9301 affects VideoLAN VLC media player version 2.2.4 and prior.
4
What impact can CVE-2017-9301 have?
CVE-2017-9301 can cause application crashes and potentially other unspecified impacts.
5
Can CVE-2017-9301 be exploited remotely?
Yes, remote attackers can exploit CVE-2017-9301 through specially crafted files.