CVE-2018-11529: Use After Free
Published Jul 11, 2018
·Updated
VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV files. Failed exploit attempts will likely result in denial of service conditions.
Affected Software
3 affected componentsFixes available
debian/vlc
3.0.17.4-0+deb10u13.0.17.4-0+deb10u23.0.18-0+deb11u13.0.18-23.0.19-1
Debian Debian Linux=9.0
Videolan VLC Media Player<=2.2.8
Event History
Jul 11, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-11529?
CVE-2018-11529 is a use after free vulnerability in VideoLAN VLC media player 2.2.x.
2
How can an attacker exploit CVE-2018-11529?
An attacker can exploit CVE-2018-11529 by leveraging the use after free vulnerability to execute arbitrary code via crafted MKV files.
3
What is the severity of CVE-2018-11529?
CVE-2018-11529 has a severity level of high (8).
4
How can I fix CVE-2018-11529?
To fix CVE-2018-11529, update VideoLAN VLC media player to version 3.0.17.4-0+deb10u1, 3.0.17.4-0+deb10u2, 3.0.18-0+deb11u1, 3.0.18-2, or 3.0.19-1.
5
Where can I find more information about CVE-2018-11529?
More information about CVE-2018-11529 can be found at the following references: [1] [2] [3].