VDB

GCVE-110-MAGEIA-2021-227

GCVE-110-MAGEIA-2021-227
Advisory Published
Vulnetix · Advisory published June 8, 2021
A remote user could create a specifically crafted file that could trigger some various issues. It is possible to trigger a remote code execution through a specifically crafted playlist, and tricking the user into interacting with that playlist elements. It is also possible to trigger read or write buffer overflows with some crafted files or by a MITM attack on the automatic updater If successful, a malicious third party could trigger either a crash of VLC or an arbitratry code execution with the privileges of the target user. We updated VLC to latest version available.

Affected Products

VendorProductVersionsPlatforms
Mageiavlc3.0.14-1.mga8 (unaffected), 0 (affected), 0 (affected), 0 (affected), 3.0.14-1.mga8 (unaffected), 0 (affected), 3.0.14-1.mga8.tainted (unaffected), 3.0.14-1.mga8.tainted (unaffected)
Mageiavlc3.0.14-1.mga7 (unaffected), 0 (affected), 3.0.14-1.mga7.tainted (unaffected), 3.0.14-1.mga7 (unaffected), 3.0.14-1.mga7.tainted (unaffected), 0 (affected), 0 (affected), 0 (affected)
Mageiakodi0 (affected), 0 (affected), 19.3-1.mga8.tainted (unaffected), 19.3-1.mga8 (unaffected)

Browse GCVE Records

74,147 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›