Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
VideoLAN VLC 缓冲区错误漏洞
Vulnerability Description
VideoLAN VLC是法国VideoLAN组织开发的一款免费、开源的跨平台多媒体播放器(也是一个多媒体框架)。该产品支持播放多种介质(文件、光盘等)、多种音视频格式(WMV, MP3等)等。ParseJSS是其中的一个字幕文件解析器。 VideoLAN VLC 2.2.5之前的版本中的ParseJSS存在基于堆的缓冲区溢出漏洞。攻击者可借助特制的字幕文件利用该漏洞执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A