CVE-2022-41325: Integer Overflow
An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-41325?
CVE-2022-41325 is an integer overflow vulnerability in the VNC module of VideoLAN VLC Media Player through version 3.0.17.4.
How does CVE-2022-41325 work?
CVE-2022-41325 can be exploited by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, which can cause VLC to crash or execute arbitrary code.
Is Videolan VLC Media Player affected by CVE-2022-41325?
Yes, Videolan VLC Media Player through version 3.0.17.4 is affected by CVE-2022-41325.
Is Debian Linux affected by CVE-2022-41325?
Yes, Debian Linux version 11.0 is affected by CVE-2022-41325.
How can I fix CVE-2022-41325?
To fix CVE-2022-41325, users should update to the latest version of VideoLAN VLC Media Player or apply the relevant security patches provided by Debian.