|
|
Log in / Subscribe / Register

vlc: code execution

Package(s):vlc CVE #(s):CVE-2014-6440
Created:March 6, 2015 Updated:March 11, 2015
Description:

From the Mageia advisory:

VLC versions before 2.1.5 contain a vulnerability in the transcode module that may allow a corrupted stream to overflow buffers on the heap. With a non-malicious input, this could lead to heap corruption and a crash. However, under the right circumstances, a malicious attacker could potentially use this vulnerability to hijack program execution, and on some platforms, execute arbitrary code.

Alerts:
Gentoo 201603-08 vlc 2016-03-12
Mageia MGASA-2015-0095 vlc 2015-03-05

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds