HTTP: VideoLan VLC Media Player ParseJSS Heap Buffer Overflow

This signature detects attempts to exploit a known vulnerability in VLC Media Player. Successful exploitation could result in arbitrary code execution in the context of the user.

Extended Description

Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.

Affected Products

Videolan vlc_media_player

References

CVE: CVE-2017-8311

Short Name
HTTP:STC:DL:VLC-MP-BO
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Buffer CVE-2017-8311 Heap Media Overflow ParseJSS Player VLC VideoLan
Release Date
06/20/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Videolan

CVSS Score

6.8

Found a potential security threat?