A divide-by-zero error exists in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted CAF file.
The product divides a value by zero.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Vlc_media_player | Videolan | 3.0.7.1 (including) | 3.0.7.1 (including) |
| Vlc | Ubuntu | bionic | * |
| Vlc | Ubuntu | disco | * |
| Vlc | Ubuntu | esm-apps/bionic | * |
| Vlc | Ubuntu | esm-apps/xenial | * |
| Vlc | Ubuntu | trusty | * |
| Vlc | Ubuntu | upstream | * |
| Vlc | Ubuntu | xenial | * |