An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.
| Software | From | Fixed in |
|---|---|---|
| videolan / vlc_media_player | - | 3.0.17.4.x |
| debian / debian_linux | 11.0 | 11.0.x |