CVE-2017-8312
Publication date 23 May 2017
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a crafted subtitles file.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| vlc | ||
| 16.04 LTS xenial |
Fixed 2.2.2-5ubuntu0.16.04.3
|
|
| 14.04 LTS trusty |
Fixed 2.1.6-0ubuntu14.04.3
|
Patch details
| Package | Patch details |
|---|---|
| vlc |
Severity score breakdown
CVSS version: CVSS v3.0
Base score
5.5 · Medium
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N