CVE-2021-25802 PUBLISHED

A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

EPSS 0.28% · 51.4th percentile

Risk Scores

EPSS Score
0.28%
51.4th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSvlc3.0.0~rc8-1ubuntu1, 3.0.0-1ubuntu1, 3.0.1-1ubuntu5
Ubuntu:Pro:16.04:LTSvlc2.2.2-1, 2.2.1-5, 2.2.2-2
Ubuntu:Pro:20.04:LTSvlc0, 3.0.8-2, 3.0.8-2build1

Timeline

References

Open in Interactive Console →