CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
Percentile
95.0%
Severity: High
Date : 2017-06-01
CVE-ID : CVE-2017-8310 CVE-2017-8311 CVE-2017-8312
Package : vlc
Type : multiple issues
Remote : No
Link : https://security.archlinux.org/AVG-283
The package vlc before version 2.2.6-1 is vulnerable to multiple issues
including arbitrary code execution and denial of service.
Upgrade to 2.2.6-1.
The problems have been fixed upstream in version 2.2.6.
None.
Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due
to missing check of string termination allows attackers to read data
beyond allocated memory and potentially crash the process (causing a
denial of service) via a crafted subtitles file.
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before
2.2.5 due to skipping NULL terminator in an input string allows
attackers to execute arbitrary code via a crafted subtitles file.
Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check
of string length allows attackers to read heap uninitialized data via a
crafted subtitles file.
A local attacker is able to use a specially crafted subtitles file to
crash the application or execute arbitrary code on the affected host.
https://bugs.archlinux.org/task/54194
http://git.videolan.org/?p=vlc/vlc-2.2.git;a=commitdiff;h=7cac839692ab79dbfe5e4ebd4c4e37d9a8b1b328
http://git.videolan.org/?p=vlc.git;a=commitdiff;h=775de716add17322f24b476439f903a829446eb6
http://git.videolan.org/?p=vlc.git;a=commitdiff;h=611398fc8d32f3fe4331f60b220c52ba3557beaa
https://security.archlinux.org/CVE-2017-8310
https://security.archlinux.org/CVE-2017-8311
https://security.archlinux.org/CVE-2017-8312
git.videolan.org/?p=vlc.git;a=commitdiff;h=611398fc8d32f3fe4331f60b220c52ba3557beaa
git.videolan.org/?p=vlc.git;a=commitdiff;h=775de716add17322f24b476439f903a829446eb6
git.videolan.org/?p=vlc/vlc-2.2.git;a=commitdiff;h=7cac839692ab79dbfe5e4ebd4c4e37d9a8b1b328
bugs.archlinux.org/task/54194
security.archlinux.org/AVG-283
security.archlinux.org/CVE-2017-8310
security.archlinux.org/CVE-2017-8311
security.archlinux.org/CVE-2017-8312
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
Percentile
95.0%