CVE-2024-46461

HIGH8.0EPSS 0.35%

vlc - security update

發布日:2024/9/25修改日:2026/3/9
也稱為:DSA-5707-1DEBIAN-CVE-2024-46461

描述

VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH8.0CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

參考連結(1)