Medium severity5.5NVD Advisory· Published May 23, 2017· Updated May 13, 2026
CVE-2017-8310
CVE-2017-8310
Description
Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file.
Affected products
7cpe:2.3:a:videolan:vlc_media_player:2.2.0:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:videolan:vlc_media_player:2.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:videolan:vlc_media_player:2.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:videolan:vlc_media_player:2.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:videolan:vlc_media_player:2.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:videolan:vlc_media_player:2.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:videolan:vlc_media_player:2.2.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/98638nvdThird Party AdvisoryVDB Entry
- www.debian.org/security/2017/dsa-3899nvd
- security.gentoo.org/glsa/201707-10nvd
News mentions
0No linked articles in our index yet.