Buffer overflow in VLC Media Player - CVE-2016-5108

 

Buffer overflow in VLC Media Player - CVE-2016-5108

Published: June 24, 2016 / Updated: February 27, 2025


Vulnerability identifier: #VU23
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5108
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to boundary error within the DecodeAdpcmImaQT() function in modules/codec/adpcm.c when processing QuickTime IMA Files. A remote attacker can trick the victim into opening a specially crafted media file, trigger memory corruption and execute arbitrary code on the system.


Affected software

VLC Media Player
Arch Linux
Debian Linux
Gentoo Linux
vlc (Alpine package)

How to mitigate CVE-2016-5108

Install update from vendor's website.

VLC Media Player - update to 2.2.4
vlc (Alpine package) - update to 2.1.6-r1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins