VDB
GCVE-110-MAGEIA-2021-227
GCVE-110-MAGEIA-2021-227
Advisory Published
A remote user could create a specifically crafted file that could trigger some various issues.
It is possible to trigger a remote code execution through a specifically crafted playlist, and tricking the user into interacting with that playlist elements.
It is also possible to trigger read or write buffer overflows with some crafted files or by a MITM attack on the automatic updater
If successful, a malicious third party could trigger either a crash of VLC or an arbitratry code execution with the privileges of the target user.
We updated VLC to latest version available.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | vlc | 3.0.14-1.mga8 (unaffected), 0 (affected), 0 (affected), 0 (affected), 3.0.14-1.mga8 (unaffected), 0 (affected), 3.0.14-1.mga8.tainted (unaffected), 3.0.14-1.mga8.tainted (unaffected) | — |
| Mageia | vlc | 3.0.14-1.mga7 (unaffected), 0 (affected), 3.0.14-1.mga7.tainted (unaffected), 3.0.14-1.mga7 (unaffected), 3.0.14-1.mga7.tainted (unaffected), 0 (affected), 0 (affected), 0 (affected) | — |
| Mageia | kodi | 0 (affected), 0 (affected), 19.3-1.mga8.tainted (unaffected), 19.3-1.mga8 (unaffected) | — |
References
Browse GCVE Records
74,147 records in the GCVE database · Updated July 21, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.