CVE-2023-47359: Buffer Overflow
Published Nov 7, 2023
·Updated
Last updated 24 July 2024
Other sources
Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption.
Affected Software
2 affected componentsFixes available
debian/vlc
3.0.21-0+deb11u13.0.21-0+deb12u13.0.21-2
Videolan VLC Media Player<3.0.20
Remediation
Event History
Nov 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
May 23, 2024
Data Sourced
via Launchpad·09:25 AM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·09:42 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-47359?
The severity of CVE-2023-47359 is critical.
2
What is the affected software for CVE-2023-47359?
The affected software for CVE-2023-47359 is Videolan VLC Media Player version up to 3.0.20.
3
What is the vulnerability in CVE-2023-47359?
The vulnerability in CVE-2023-47359 is a Heap-Based Buffer Overflow in the GetPacket() function, leading to memory corruption.
4
How can the vulnerability in CVE-2023-47359 be exploited?
The vulnerability in CVE-2023-47359 can be exploited by an attacker through an incorrect offset read.
5
Is there a fix available for CVE-2023-47359?
Yes, the fix for CVE-2023-47359 is to update to version 3.0.20 of Videolan VLC Media Player.