VLC: Buffer overflow — GLSA 201701-39

A buffer overflow in VLC might allow remote attackers to execute arbitrary code.

Affected packages

media-video/vlc on all architectures
Affected versions < 2.2.4
Unaffected versions >= 2.2.4

Background

VLC is a cross-platform media player and streaming server.

Description

A buffer overflow was discovered in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in the VideoLAN VLC media player.

Impact

Remote attackers, by enticing a user to execute a specially crafted QuickTime IMA file, could cause a Denial of Service condition or possibly execute arbitrary code.

Workaround

There is no known workaround at this time.

Resolution

All VLC users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=media-video/vlc-2.2.4"
 

References

Release date
January 17, 2017

Latest revision
January 17, 2017: 01

Severity
normal

Exploitable
remote

Bugzilla entries