VLC: Buffer overflow A buffer overflow in VLC might allow remote attacker(s) to execute arbitrary code. vlc 2021-01-29 2021-01-29 765040 remote 3.0.12.1 3.0.12.1

VLC is a cross-platform media player and streaming server.

VLC was found to have a buffer overflow when handling crafted MKV files.

A remote attacker could entice a user to open a specially crafted MKV file using VLC possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition.

There is no known workaround at this time.

All VLC users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=media-video/vlc-3.0.12.1"
CVE-2020-26664 sam_c sam_c