CVE-2014-9627 PUBLISHED

The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large box size.

EPSS 0.34% · 56.4th percentile

Risk Scores

EPSS Score
0.34%
56.4th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSvlc0, 2.0.8-1, 2.1.1-1

Timeline

References

Open in Interactive Console →