Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-9625
Description:The GetUpdateFile function in misc/update.c in the Updater in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a crafted update status file, aka an "integer truncation" vulnerability.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-9625
http://openwall.com/lists/oss-security/2015/01/20/5
https://github.com/videolan/vlc/commit/fbe2837bc80f155c001781041a54c58b5524fc14




© 1998-2025 E-Soft Inc. All rights reserved.