A heap-based buffer overflow in the hxxx_AnnexB_to_xVC...
Moderate severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Mar 3, 2023
Description
Published by the National Vulnerability Database
Jun 8, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Mar 3, 2023
A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player through 3.2.8 for iOS, and through 3.0.10 for macOS, allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file.
References