CVE-2017-17670

NameCVE-2017-17670
DescriptionIn VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerability in modules/demux/mp4/libmp4.c in the MP4 demux module leading to a invalid free, because the type of a box may be changed between a read operation and a free operation.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-4203-1
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
vlc (PTS)jessie (security), jessie2.2.7-1~deb8u1vulnerable
stretch (security), stretch3.0.2-0+deb9u1fixed
buster, sid3.0.3-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
vlcsource(unstable)3.0.0~rc2-1medium
vlcsourcejessie(unfixed)end-of-life
vlcsourcestretch3.0.2-0+deb9u1mediumDSA-4203-1
vlcsourcewheezy(unfixed)end-of-life

Notes

[jessie] - vlc <end-of-life> (See DSA-4203-1)
[wheezy] - vlc <end-of-life> (Not supported in wheezy LTS)
http://www.openwall.com/lists/oss-security/2017/12/15/1
POC: https://gist.github.com/dyntopia/194d912287656f66dd502158b0cd2e68

Search for package or bug name: Reporting problems