CVE-2018-11529

NameCVE-2018-11529
DescriptionVideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV files. Failed exploit attempts will likely result in denial of service conditions.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-4251-1
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
vlc (PTS)stretch3.0.11-0+deb9u1fixed
stretch (security)3.0.11-0+deb9u2fixed
buster, buster (security)3.0.12-0+deb10u1fixed
bookworm, sid, bullseye3.0.16-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
vlcsourcejessie(unfixed)end-of-life
vlcsourcestretch3.0.3-1-0+deb9u1DSA-4251-1
vlcsource(unstable)3.0.3-1-1

Notes

[jessie] - vlc <end-of-life> (See https://lists.debian.org/debian-security-announce/2018/msg00130.html)
https://github.com/videolan/vlc-3.0/commit/c472668ff873cfe29281822b4548715fb7bb0368
https://github.com/videolan/vlc-3.0/commit/d2dadb37e7acc25ae08df71e563855d6e17b5b42

Search for package or bug name: Reporting problems