Vulnerability Name: | CVE-2017-8313 (CCN-126872) | ||||||||||||||||
Assigned: | 2017-05-23 | ||||||||||||||||
Published: | 2017-05-23 | ||||||||||||||||
Updated: | 2017-11-04 | ||||||||||||||||
Summary: | Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process via a crafted subtitles file. | ||||||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
5.3 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-125 | ||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-8313 Source: CCN Type: VideoLAN GIT Repository demux/subtitle: ParseJSS: fix out-of-bounds read Source: CONFIRM Type: Patch http://git.videolan.org/?p=vlc/vlc-2.2.git;a=commitdiff;h=05b653355ce303ada3b5e0e645ae717fea39186c Source: DEBIAN Type: UNKNOWN DSA-3899 Source: BID Type: UNKNOWN 98633 Source: CCN Type: BID-98633 VLAN VLC CVE-2017-8313 Denial of Service Vulnerability Source: XF Type: UNKNOWN videolan-cve20178313-info-disc(126872) Source: GENTOO Type: UNKNOWN GLSA-201707-10 Source: CCN Type: WhiteSource Vulnerability Database CVE-2017-8313 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |