USN-7243-1: VLC vulnerability
Published Jan 30, 2025
·Updated
It was discovered that VLC incorrectly handled memory when reading an MMS stream. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code.
Affected Software
10 affected componentsFixes available
All of the following
ubuntu/vlc<3.0.20-3ubuntu0.1~esm1
3.0.20-3ubuntu0.1~esm1
Ubuntu Ubuntu=24.04
All of the following
ubuntu/vlc<3.0.16-1ubuntu0.1~esm3
3.0.16-1ubuntu0.1~esm3
Ubuntu Ubuntu=22.04
All of the following
ubuntu/vlc<3.0.9.2-1ubuntu0.1~esm3
3.0.9.2-1ubuntu0.1~esm3
Ubuntu Ubuntu=20.04
All of the following
ubuntu/vlc<3.0.8-0ubuntu18.04.1+esm3
3.0.8-0ubuntu18.04.1+esm3
Ubuntu Ubuntu=18.04
All of the following
ubuntu/vlc<2.2.2-5ubuntu0.16.04.5+esm4
2.2.2-5ubuntu0.16.04.5+esm4
Ubuntu Ubuntu=16.04
Event History
Jan 30, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7243-1?
The severity of USN-7243-1 is significant, as it can lead to denial of service or arbitrary code execution.
2
How do I fix USN-7243-1?
To fix USN-7243-1, upgrade VLC to the specified remedied versions for your Ubuntu distribution.
3
Which versions of VLC are affected by USN-7243-1?
USN-7243-1 affects various VLC versions, including 3.0.20, 3.0.16, 3.0.9.2, 3.0.8, and 2.2.2 across different Ubuntu releases.
4
Can USN-7243-1 be exploited remotely?
Yes, USN-7243-1 can potentially be exploited remotely through specially crafted MMS streams.
5
What products are impacted by USN-7243-1?
USN-7243-1 impacts VLC media player on Ubuntu versions 16.04, 18.04, 20.04, 22.04, and 24.04.