CVE
CVE-2016-3941
Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF."
- Severity
- MEDIUM
- CVSS
- 5.5
- Published
- Modified
Linked Releases
| Distribution | Release | Status | Evidence |
|---|---|---|---|
| Ubuntu | 14.04.6 amd64 desktop | unknown | source |
| Ubuntu | 14.04.6 i386 desktop | unknown | source |
| Ubuntu | 14.04.6 amd64 server | unknown | source |
| Ubuntu | 14.04.6 i386 server | unknown | source |
References
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00045.html
- http://www.securitytracker.com/id/1035456
- https://bugs.launchpad.net/ubuntu/+source/vlc/+bug/1533633
- https://mailman.videolan.org/pipermail/vlc-commits/2015-January/028938.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00045.html
- http://www.securitytracker.com/id/1035456
- https://bugs.launchpad.net/ubuntu/+source/vlc/+bug/1533633
- https://mailman.videolan.org/pipermail/vlc-commits/2015-January/028938.html