CVE-2017-8311
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.
- Videolan Vlc Media Player
- ≤ 2.2.4
- Fix
- Available
- CVSS 3.0
- 7.8 HIGH
- EPSS
- 8.8% (95th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2017-05-23
CVE-2017-8311 at NVD
4 known exploits for CVE-2017-8311
Proof-of-concept code and exploit modules indexed by Sploitus