CVE-2017-17670

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
15/12/2017
Last modified:
20/04/2025

Description

In VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerability in modules/demux/mp4/libmp4.c in the MP4 demux module leading to a invalid free, because the type of a box may be changed between a read operation and a free operation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:*:*:* 2.2.8 (including)
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*