CVE-2022-41325

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
06/12/2022
Last modified:
23/04/2025

Description

An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:*:*:* 3.0.17.4 (including)
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*