VDB

DEBIAN-CVE-2024-46461

DEBIAN-CVE-2024-46461 PUBLISHED CVSS 8 HIGH

VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges.

Risk Scores

CVSS 3.1
8
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:11vlc3.0.19-1, 3.0.17-1, 3.0.17.3-1
Debian:12vlc3.0.18-2, 3.0.20-1, 3.0.20-2
Debian:13vlc0, 0
Debian:14vlc0, 0

Timeline

  • Sep 25, 2024 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›