CVE-2016-3941

Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF."
Configurations

Configuration 1 (hide)

cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

History

21 Nov 2024, 02:50

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00045.html - () http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00045.html -
References () http://www.securitytracker.com/id/1035456 - () http://www.securitytracker.com/id/1035456 -
References () https://bugs.launchpad.net/ubuntu/+source/vlc/+bug/1533633 - Vendor Advisory () https://bugs.launchpad.net/ubuntu/+source/vlc/+bug/1533633 - Vendor Advisory
References () https://mailman.videolan.org/pipermail/vlc-commits/2015-January/028938.html - Exploit () https://mailman.videolan.org/pipermail/vlc-commits/2015-January/028938.html - Exploit

Information

Published : 2016-04-18 15:59

Updated : 2024-11-21 02:50


NVD link : CVE-2016-3941

Mitre link : CVE-2016-3941

CVE.ORG link : CVE-2016-3941


JSON object : View

Products Affected

canonical

  • ubuntu_linux

videolan

  • vlc_media_player
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer