GCVE-VVD-MAGEIA-2017-424
Advisory Published
Vulnetix · Advisory published November 26, 2017
avcodec 2.2.x, as used in VideoLAN VLC media player before 2.2.7, allows
out-of-bounds heap memory write due to calling memcpy() with a wrong
size, leading to a denial of service (application crash) or possibly
code execution (CVE-2017-10699).
The VLC packages have been updated to version 2.2.8, which includes
various security improvements in decoders and demuxers, as well as other
bug fixes.