Vulnerability Description
mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01 response from an MMS server.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://code.videolan.org/videolan/vlc/-/issues/29146
- https://www.videolan.org/security/sb-vlc3022.html
- https://lists.debian.org/debian-lts-announce/2026/03/msg00011.html
FAQ
What is CVE-2025-51602?
CVE-2025-51602 is a vulnerability with a CVSS score of 4.8 (MEDIUM). mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01 response from an MMS server.
How severe is CVE-2025-51602?
CVE-2025-51602 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-51602?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.