CVE-2021-25801: Buffer Overflow
Published Jul 26, 2021
·Updated
A buffer overflow vulnerability in the Parseindx component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.
Affected Software
1 affected component
Videolan VLC Media Player=3.0.11
Event History
Jul 26, 2021
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
Description
Frequently Asked Questions
1
What is CVE-2021-25801?
CVE-2021-25801 is a buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11.
2
How does CVE-2021-25801 affect VideoLAN VLC Media Player?
CVE-2021-25801 allows attackers to cause an out-of-bounds read in VideoLAN VLC Media Player 3.0.11 through a crafted .avi file.
3
What is the severity of CVE-2021-25801?
CVE-2021-25801 has a severity rating of 7.1 (high).
4
How can I fix CVE-2021-25801 in VideoLAN VLC Media Player?
To fix CVE-2021-25801, upgrade VideoLAN VLC Media Player to a version higher than 3.0.11.
5
Is there any additional information about CVE-2021-25801?
More information about CVE-2021-25801 can be found at: https://code.videolan.org/videolan/vlc-3.0/-/commit/f5f8cc3ab8825f178de3f6714bfbff8b3f293fd2