← back
CVE-2017-8311

CVE-2017-8311

EPSS 8.8%
Vexday Risk Score
23Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS EPSS 8.8%KEV nãoPoC públicaNuclei Metasploit Patch referenciado
Lifecycle
23 May 2017Published on NVD
24 Apr 2018Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.
Affected products
VideoLAN · VLC
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →