Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file.
| Software | From | Fixed in |
|---|---|---|
| videolan / vlc_media_player | 2.2.4 | 2.2.4.x |
| videolan / vlc_media_player | 2.2.2 | 2.2.2.x |
| videolan / vlc_media_player | 2.2.3 | 2.2.3.x |
| videolan / vlc_media_player | 2.2.1 | 2.2.1.x |
| videolan / vlc_media_player | 2.2.0 | 2.2.0.x |
| videolan / vlc_media_player | 2.2.5 | 2.2.5.x |