Candidate: CVE-2020-26664 PublicDate: 2021-01-08 18:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26664 https://code.videolan.org/videolan/vlc-3.0/-/commit/ec1f55ee9ace5cc675395a1bc9700d99679e7e8c (3.0.12) https://gist.githubusercontent.com/henices/db11664dd45b9f322f8514d182aef5ea/raw/d56940c8bf211992bf4f3309a85bb2b69383e511/CVE-2020-26664.txt http://videolan.com http://vlc.com Description: A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=979676 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_vlc: upstream_vlc: needs-triage precise/esm_vlc: DNE trusty_vlc: ignored (out of standard support) trusty/esm_vlc: DNE xenial_vlc: ignored (end of standard support, was needs-triage) bionic_vlc: needs-triage focal_vlc: needs-triage groovy_vlc: ignored (reached end-of-life) hirsute_vlc: ignored (reached end-of-life) impish_vlc: needs-triage jammy_vlc: needs-triage devel_vlc: needs-triage