CVE-2017-8313
MEDIUMHeap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process via a crafted subtitles file.
Published: 5/23/2017Modified: 5/13/2026
References (8)
http://git.videolan.org/?p=vlc/vlc-2.2.git%3Ba=commitdiff%3Bh=05b653355ce303ada3b5e0e645ae717fea39186chttp://www.debian.org/security/2017/dsa-3899http://www.securityfocus.com/bid/98633https://security.gentoo.org/glsa/201707-10http://git.videolan.org/?p=vlc/vlc-2.2.git%3Ba=commitdiff%3Bh=05b653355ce303ada3b5e0e645ae717fea39186chttp://www.debian.org/security/2017/dsa-3899http://www.securityfocus.com/bid/98633https://security.gentoo.org/glsa/201707-10