Bug ID 1206142
Summary VUL-0: CVE-2022-41325: vlc: security update 3.0.18
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.4
Hardware Other
URL https://smash.suse.de/issue/349957/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee dimstar@opensuse.org
Reporter thomas.leroy@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2022-41325

An integer overflow in the VNC module in VideoLAN VLC Media Player through
3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist
or
connecting to a rogue VNC server, to crash VLC or execute code under some
conditions.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-41325
https://security-tracker.debian.org/tracker/DSA-5297-1
https://www.cve.org/CVERecord?id=CVE-2022-41325
https://www.videolan.org/security/sb-vlc3018.html
https://www.synacktiv.com/sites/default/files/2022-11/vlc_vnc_int_overflow-CVE-2022-41325.pdf
https://twitter.com/0xMitsurugi


You are receiving this mail because: