The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies in CAF files, because a ReadKukiChunk() cast converts a return value to an unsigned int even if that value is negative. This could result in a denial of service and/or a potential infoleak.
{ "binaries": [ { "binary_name": "libvlc-dev", "binary_version": "2.2.2-5ubuntu0.16.04.5+esm4" }, { "binary_name": "libvlc5", "binary_version": "2.2.2-5ubuntu0.16.04.5+esm4" }, { "binary_name": "libvlccore-dev", "binary_version": "2.2.2-5ubuntu0.16.04.5+esm4" }, { "binary_name": "libvlccore8", "binary_version": "2.2.2-5ubuntu0.16.04.5+esm4" }, { "binary_name": "vlc", "binary_version": "2.2.2-5ubuntu0.16.04.5+esm4" }, { "binary_name": "vlc-data", "binary_version": "2.2.2-5ubuntu0.16.04.5+esm4" }, { "binary_name": "vlc-nox", "binary_version": "2.2.2-5ubuntu0.16.04.5+esm4" }, { "binary_name": "vlc-plugin-fluidsynth", "binary_version": "2.2.2-5ubuntu0.16.04.5+esm4" }, { "binary_name": "vlc-plugin-jack", "binary_version": "2.2.2-5ubuntu0.16.04.5+esm4" }, { "binary_name": "vlc-plugin-notify", "binary_version": "2.2.2-5ubuntu0.16.04.5+esm4" }, { "binary_name": "vlc-plugin-samba", "binary_version": "2.2.2-5ubuntu0.16.04.5+esm4" }, { "binary_name": "vlc-plugin-sdl", "binary_version": "2.2.2-5ubuntu0.16.04.5+esm4" }, { "binary_name": "vlc-plugin-svg", "binary_version": "2.2.2-5ubuntu0.16.04.5+esm4" }, { "binary_name": "vlc-plugin-zvbi", "binary_version": "2.2.2-5ubuntu0.16.04.5+esm4" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "libvlc-bin", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "libvlc-dev", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "libvlc5", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "libvlccore-dev", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "libvlccore9", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "vlc", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "vlc-bin", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "vlc-data", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "vlc-l10n", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "vlc-plugin-access-extra", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "vlc-plugin-base", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "vlc-plugin-fluidsynth", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "vlc-plugin-jack", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "vlc-plugin-notify", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "vlc-plugin-qt", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "vlc-plugin-samba", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "vlc-plugin-skins2", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "vlc-plugin-svg", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "vlc-plugin-video-output", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "vlc-plugin-video-splitter", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "vlc-plugin-visualization", "binary_version": "3.0.7.1-0ubuntu18.04.1" }, { "binary_name": "vlc-plugin-zvbi", "binary_version": "3.0.7.1-0ubuntu18.04.1" } ] }