Unrated severityNVD Advisory· Published Jun 8, 2020· Updated Aug 4, 2024
CVE-2020-13428
CVE-2020-13428
Description
A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file.
Affected products
6- VideoLAN/VLC media playerdescription
- osv-coords5 versionspkg:rpm/opensuse/vlc&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/vlc&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/vlc&distro=openSUSE%20Tumbleweedpkg:rpm/suse/vlc&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/vlc&distro=SUSE%20Package%20Hub%2015%20SP2
< 3.0.11.1-lp151.6.12.1+ 4 more
- (no CPE)range: < 3.0.11.1-lp151.6.12.1
- (no CPE)range: < 3.0.11.1-lp152.2.9.1
- (no CPE)range: < 3.0.16-1.5
- (no CPE)range: < 3.0.11.1-bp151.5.12.1
- (no CPE)range: < 3.0.11.1-bp152.2.9.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.debian.org/security/2020/dsa-4704mitrevendor-advisoryx_refsource_DEBIAN
- git.videolan.orgmitrex_refsource_MISC
- github.com/videolan/vlc-3.0/releases/tag/3.0.11mitrex_refsource_CONFIRM
- github.com/videolan/vlc/commits/master/modules/packetizer/hxxx_nal.cmitrex_refsource_MISC
- www.videolan.org/security/sb-vlc3011.htmlmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.