An off-by-one error in the DecodeBlock function in codec/sdlimage.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDLImage product.
{
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.0.9"
}
],
"cpe": "cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:*:*:*"
}