VideoLAN Security Bulletin VLC 3.0.21
Summary : Vulnerability fixed in VLC media player
Date : June 2024
Affected versions : VLC media player 3.0.20 and earlier
ID : VideoLAN-SB-VLC-3021
Details
A denial of service through a potential integer overflow could be triggered with a maliciously crafted mms stream (heap based overflow)
Impact
If successful, a malicious third party could trigger either a crash of VLC or an arbitratry code execution with the privileges of the target user.
While these iss...
Read more at videolan.org