CVE-2020-26664: Buffer Overflow
A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/vlcto a version that resolves this vulnerability.Fixed in 3.0.17.4-0+deb10u1Fixed in 3.0.17.4-0+deb10u2Fixed in 3.0.18-0+deb11u1Fixed in 3.0.18-2Fixed in 3.0.19-1 - Upgrade
Upgrade
debian/vlcto a version that resolves this vulnerability.Fixed in 3.0.12-1Fixed in 3.0.12-0+deb10u1
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26664?
The severity of CVE-2020-26664 is high with a CVSS score of 7.8.
How does CVE-2020-26664 affect VideoLAN VLC media player?
CVE-2020-26664 allows attackers to trigger a heap-based buffer overflow in VideoLAN VLC media player 3.0.11.
How can I exploit CVE-2020-26664?
To exploit CVE-2020-26664, attackers need to use a crafted .mkv file.
What is the remediation for CVE-2020-26664 in Debian Debian Linux 10.0?
To remediate CVE-2020-26664 in Debian Debian Linux 10.0, update the VLC package to version 3.0.19-1 or later.
Where can I find more information about CVE-2020-26664?
For more information about CVE-2020-26664, you can refer to the following references: [1](https://security-tracker.debian.org/tracker/CVE-2020-26664), [2](https://code.videolan.org/videolan/vlc-3.0/-/commit/ec1f55ee9ace5cc675395a1bc9700d99679e7e8c), [3](https://gist.githubusercontent.com/henices/db11664dd45b9f322f8514d182aef5ea/raw/d56940c8bf211992bf4f3309a85bb2b69383e511/CVE-2020-26664.txt)