CVE-2020-13428: Buffer Overflow
A heap-based buffer overflow in the hxxxAnnexBtoxVC function in modules/packetizer/hxxxnal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-13428?
CVE-2020-13428 is a heap-based buffer overflow vulnerability in the hxxx_AnnexB_to_xVC function in VLC media player before 3.0.11 for macOS/iOS.
How does CVE-2020-13428 affect VLC media player?
CVE-2020-13428 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code by exploiting the vulnerability.
Which versions of VLC media player are affected by CVE-2020-13428?
VLC media player versions before 3.0.11 for macOS/iOS are affected by CVE-2020-13428.
How can I fix CVE-2020-13428?
To fix CVE-2020-13428, update VLC media player to version 3.0.11 or later.
Where can I find more information about CVE-2020-13428?
More information about CVE-2020-13428 can be found in the references provided: [link1], [link2], [link3].