KLA10990
Vulnerability in VideoLAN VLC media player
Updated: 06/17/2019
Detect date
?
06/19/2014
Severity
?
Critical
Description

A vulnerability in the transcode module was found in VLC media player versions before 2.1.5. By exploiting this vulnerability malicious users can cause a denial of service or execute arbitrary code. This vulnerability can be exploited remotely via a non-malicious input.


Technical details

This vulnerability can allow a corrupted stream to cause a buffer overflow on the heap.

NB: This vulnerability have no public CVSS rating so rating can be changed by the time.

Affected products

VideoLAN VLC media player earlier than 2.1.5

Solution

Update to the latest version
Download VLC media player

Original advisories

VLC news

Impacts
?
ACE 
[?]

DoS 
[?]
CVE-IDS
?
CVE-2014-64407.5Critical