Unrated severityNVD Advisory· Published Dec 6, 2022· Updated Apr 23, 2025
CVE-2022-41325
CVE-2022-41325
Description
An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.
Affected products
8- VideoLAN/VLC Media Playerdescription
- osv-coords7 versionspkg:rpm/opensuse/vlc&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/vlc&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/vlc&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/vlc&distro=openSUSE%20Tumbleweedpkg:rpm/suse/vlc&distro=SUSE%20Package%20Hub%2015%20SP3pkg:rpm/suse/vlc&distro=SUSE%20Package%20Hub%2015%20SP4pkg:rpm/suse/vlc&distro=SUSE%20Package%20Hub%2015%20SP5
< 3.0.18-bp153.2.6.1+ 6 more
- (no CPE)range: < 3.0.18-bp153.2.6.1
- (no CPE)range: < 3.0.18-bp154.2.3.1
- (no CPE)range: < 3.0.20-bp155.2.3.1
- (no CPE)range: < 3.0.18-4.1
- (no CPE)range: < 3.0.18-bp153.2.6.1
- (no CPE)range: < 3.0.18-bp154.2.3.1
- (no CPE)range: < 3.0.20-bp155.2.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.