CVE-2016-5108 | VideoLAN VLC Media Player up to 2.2.3 Quicktime IMA File modules/codec/adpcm.c DecodeAdpcmImaQT memory corruption (EDB-41025 / Nessus ID 91581)
A vulnerability classified as critical has been found in VideoLAN VLC Media Player up to 2.2.3. Affected is the function DecodeAdpcmImaQT of the file modules/codec/adpcm.c of the component Quicktime IMA File Handler. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2016-5108. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.