CVE-2020-26664

Name
CVE-2020-26664
Description
A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Third Party Advisory http://vlc.com
Exploit https://gist.githubusercontent.com/henices/db11664dd45b9f322f8514d182aef5ea/raw/d56940c8bf211992bf4f3309a85bb2b69383e511/CVE-2020-26664.txt
Product http://videolan.com
Third Party Advisory https://www.debian.org/security/2021/dsa-4834
Third Party Advisory https://security.gentoo.org/glsa/202101-37

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:*:*:* vlc_media_player >= None < 3.0.12

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
vlc 3.13-community 3.0.12-r0 Natanael Copa <ncopa@alpinelinux.org> fixed