#VU6673 Heap-based buffer overflow in VLC Media Player - CVE-2017-8311
Published: May 24, 2017 / Updated: June 17, 2021
VLC Media Player
VideoLAN
Description
The weakness exists due to a boundary error in ParseJSS in VideoLAN VLC when processing subtitles. A remote attacker can create specially crafted subtitle file, which when loaded by the target user with the help of affected software leads to arbitrary code execution.
Successful exploitation of the vulnerability may result in full control over the affected PC.