CVE-2017-17670

NameCVE-2017-17670
DescriptionIn VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerability in modules/demux/mp4/libmp4.c in the MP4 demux module leading to a invalid free, because the type of a box may be changed between a read operation and a free operation.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
vlc (PTS)wheezy, wheezy (security)2.0.3-5+deb7u2vulnerable
jessie (security), jessie2.2.7-1~deb8u1vulnerable
stretch (security), stretch2.2.7-1~deb9u1vulnerable
buster3.0.0~rc5-1fixed
sid3.0.0~rc6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
vlcsource(unstable)3.0.0~rc2-1medium
vlcsourcewheezy(unfixed)end-of-life

Notes

[wheezy] - vlc <end-of-life> (Not supported in wheezy LTS)
http://www.openwall.com/lists/oss-security/2017/12/15/1
POC: https://gist.github.com/dyntopia/194d912287656f66dd502158b0cd2e68

Search for package or bug name: Reporting problems