CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
Percentile
99.8%
demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player
1.1.6.1 and earlier allows remote attackers to cause a denial of service
(crash) and execute arbitrary commands via a crafted MKV (WebM or Matroska)
file that triggers memory corruption, related to “class mismatching” and
the MKV_IS_ID macro.