Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux

VLC Media Player Subtitle Remote Code Execution Vulnerability (Mac OS X)
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
The host is installed with VLC media player and is prone to heap overflow vulnerability.
Insight
Insight
The flaw exists due to the poor state of security in the way media player process subtitle files and the large number of subtitle formats. There are over 25 subtitle formats in use, each with unique features and capabilities. Media player often need to parse together multiple subtitle formats to ensure coverage and provide a better user experience. Like other, similar situations which involve fragmented software, this results in numerous distinct vulnerabilities.
Affected Software
Affected Software
VideoLAN VLC media player before 2.2.5.1 on Mac OS X.
Detection Method
Detection Method
Checks if a vulnerable version is present on the target host.
Solution
Solution
Upgrade to VideoLAN VLC media player version 2.2.5.1 or later.