High severity8.8NVD Advisory· Published Dec 15, 2017· Updated May 13, 2026
CVE-2017-17670
CVE-2017-17670
Description
In VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerability in modules/demux/mp4/libmp4.c in the MP4 demux module leading to a invalid free, because the type of a box may be changed between a read operation and a free operation.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- openwall.com/lists/oss-security/2017/12/15/1nvdExploitMailing ListThird Party Advisory
- www.securityfocus.com/bid/102214nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1040938nvdThird Party AdvisoryVDB Entry
- www.debian.org/security/2018/dsa-4203nvdThird Party Advisory
News mentions
0No linked articles in our index yet.