An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.
2022-12-06T16:15:11.173
2025-04-23T20:15:41.417
Modified
CVSSv3.1: 7.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | videolan | vlc_media_player | ≤ 3.0.17.4 | Yes |
Operating System | debian | debian_linux | 11.0 | Yes |