The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large box size.
The product does not correctly convert an object, resource, or structure from one type to a different type.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vlc_media_player | Videolan | * | 2.1.6 (excluding) |
Vlc | Ubuntu | lucid | * |
Vlc | Ubuntu | precise | * |
Vlc | Ubuntu | trusty | * |
Vlc | Ubuntu | upstream | * |
Vlc | Ubuntu | utopic | * |