Total vulnerabilities in the database
The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies in CAF files, because a ReadKukiChunk() cast converts a return value to an unsigned int even if that value is negative. This could result in a denial of service and/or a potential infoleak.
Software | From | Fixed in |
---|---|---|
videolan / vlc_media_player | 3.0.4 | 3.0.4.x |
debian / debian_linux | 9.0 | 9.0.x |