Tuesday, 02 January 2024 12:17 GMT

VLC Flaws Enable Memory Corruption And Data Leakage Arabian Post


(MENAFN- The Arabian Post) clearfix">Two newly disclosed vulnerabilities affecting VLC media player 3.0.0 through 3.0.23 can corrupt heap memory or expose data when users open a malicious PNG image or connect to an attacker-controlled RealRTSP server, security records published this week show.

The more serious issue, CVE-2026-56711, is an integer-overflow flaw in VLC's picture-allocation logic that can lead to a heap out-of-bounds write. The vulnerability carries a CVSS v4 score of 8.6 and a CVSS v3.1 score of 8.8, placing it in the high-severity range.

The flaw arises when VLC calculates the size of a picture buffer using 32-bit arithmetic. Under certain dimensions, the multiplication used to determine the required memory size can wrap around to a smaller value. VLC then allocates an undersized buffer while the PNG decoder continues writing data based on the original image dimensions, allowing data to be written beyond the allocated heap region.

MENAFN12092026000152002308ID1111654881



The Arabian Post

Legal Disclaimer:
MENAFN provides the information “as is” without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the provider above.



More Story