Candidate: CVE-2017-10699 PublicDate: 2017-06-30 13:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-10699 Description: avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, allows out-of-bounds heap memory write due to calling memcpy() with a wrong size, leading to a denial of service (application crash) or possibly code execution. Ubuntu-Description: It was discovered that VLC mishandled certain crafted media files. An attacker could use this vulnerability to cause a denial of service (crash) or possibly execute arbitrary code. Notes: ratliff> notes from the upstream: ratliff> "The avcodec library does not gives bogus video sizes on 3.0, so the ratliff> issue only exists on the 2.2.x branch. Fixes have been pushed on the ratliff> 2.2.x branch and guards added as well on both versions." Bugs: https://trac.videolan.org/vlc/ticket/18467 https://bugs.launchpad.net/bugs/1715777 https://bugs.launchpad.net/bugs/1693893 Priority: medium Discovered-by: Jiaqi Peng, Bingchang Liu Assigned-to: mikesalvatore CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_vlc: upstream_vlc: needs-triage precise/esm_vlc: DNE trusty_vlc: ignored (reached end-of-life) trusty/esm_vlc: DNE (trusty was needed) vivid/ubuntu-core_vlc: DNE xenial_vlc: released (2.2.2-5ubuntu0.16.04.3) yakkety_vlc: ignored (reached end-of-life) zesty_vlc: released (2.2.4-14ubuntu2.1) artful_vlc: not-affected (2.2.6-2ubuntu1) bionic_vlc: not-affected (2.2.6-2ubuntu1) cosmic_vlc: not-affected (2.2.6-2ubuntu1) disco_vlc: not-affected (2.2.6-2ubuntu1) devel_vlc: not-affected (2.2.6-2ubuntu1)