CVE-2016-3941

MEDIUM

VLC media player <2.2.0 - Buffer Overflow

Title source: llm

Description

Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF."

Scores

CVSS v3 5.5
EPSS 0.0031
EPSS Percentile 53.6%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Classification

CWE
CWE-119
Status draft

Affected Products (2)

videolan/vlc_media_player < 2.1.6
canonical/ubuntu_linux

Timeline

Published Apr 18, 2016
Tracked Since Feb 18, 2026