KLA11759
Multiple vulnerabilities in VLC media player

Updated: 06/03/2020
Detect date
?
04/29/2020
Severity
?
Warning
Description

Multiple vulnerabilities were found in VLC media player. Malicious users can exploit these vulnerabilities to cause denial of service, execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. Vulnerability related to parsing compressed labels in mDNS messages can be exploited to cause denial of service;
  2. Vulnerability related to parsing compressed labels in mDNS messages can be exploited to execute arbitrary code;
  3. Vulnerability related to parsing the RDATA section in mDNS messages can be exploited to cause denial of service;
  4. Out-of-bound read vulnerability can be exploited to cause a denial of service;
  5. Vulnerability related to parsing mDNS messages in mdns_recv can be exploited to cause denial of service;
  6. Vulnerability related to parsing mDNS messages can be exploited to cause denial of service;
Affected products

VLC media player version 3.0.0 to 3.0.8

Solution

Update to the latest version
Download VLC media player

Original advisories

sb-vlc309

Impacts
?
ACE 
[?]

DoS 
[?]
Related products
VLC media player
CVE-IDS
?
CVE-2020-60715.0Critical
CVE-2020-60727.5Critical
CVE-2020-60735.0Critical
CVE-2020-60775.0Critical
CVE-2020-60785.0Critical
CVE-2020-60795.0Critical
Find out the statistics of the vulnerabilities spreading in your region