CVE-2024-46461: Integer Overflow
Published Sep 25, 2024
·Updated
Last updated 30 January 2025
Other sources
VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges.
— NVD
Affected Software
2 affected componentsFixes available
debian/vlc
3.0.21-0+deb11u13.0.21-0+deb12u13.0.21-7
Videolan VLC Media Player<3.0.20
Event History
Sep 25, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Jan 30, 2025
Data Sourced
via Ubuntu·04:53 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-46461?
CVE-2024-46461 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2024-46461?
To fix CVE-2024-46461, upgrade VLC media player to version 3.0.21 or later.
3
What products are affected by CVE-2024-46461?
CVE-2024-46461 affects VLC media player versions 3.0.20 and earlier.
4
What could happen if CVE-2024-46461 is exploited?
Exploitation of CVE-2024-46461 could lead to a crash of VLC media player or remote code execution.
5
Who is the vendor of the software affected by CVE-2024-46461?
The vendor of the affected software is VideoLAN.