CVE-2017-10699
CRITICALavcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, allows out-of-bounds heap memory write due to calling memcpy() with a wrong size, leading to a denial of service (application crash) or possibly code execution.
Published: 6/30/2017Modified: 5/13/2026
References (6)
http://www.securitytracker.com/id/1038816https://trac.videolan.org/vlc/ticket/18467Issue TrackingVendor Advisoryhttps://www.debian.org/security/2017/dsa-4045http://www.securitytracker.com/id/1038816https://trac.videolan.org/vlc/ticket/18467Issue TrackingVendor Advisoryhttps://www.debian.org/security/2017/dsa-4045